FIN7 (Carbanak, Carbon Spider, Sangria Tempest) — Adversary Emulation Profile
FIN7 (MITRE ATT&CK G0046; also tracked as Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS, and ITG14) is one of the most prolific and best-documented financially motivated cybercrime groups, active since at least 2013. Originally infamous for large-scale point-of-sale (POS) intrusions to steal payment-card data — operating behind the front company "Combi Security" — the group pivoted to "big game hunting" ransomware around 2020, running its own Darkside/BlackMatter Ransomware-as-a-Service and acting as an affiliate/tooling supplier for REvil, Cl0p, Black Basta, ALPHV/BlackCat, LockBit, and others. FIN7 is characterized by disciplined operational tradecraft: convincing social engineering (including spearphishing of IT staff and physically mailed BadUSB drives), heavily obfuscated custom loaders (POWERTRASH), signature backdoors (Carbanak/Anunak, Lizar/Diceloader), purchased/cracked commercial tooling (Cobalt Strike, Core Impact), and a productized EDR-killer (AvNeutralizer/AuKill) sold on criminal forums.
Attribution & motivation
- Sponsor / nation: Not a state-sponsored actor. FIN7 is an organized criminal enterprise assessed by multiple vendors to be Russian-speaking / Russia-based, with confirmed Ukrainian national members (per the 2018 U.S. DOJ indictment).
- Motivation: Financial. Early operations monetized stolen payment-card data sold on carding/darknet markets; later operations monetize via ransomware extortion (own RaaS brands and as a ransomware affiliate) and by selling intrusion tooling (e.g., the AvNeutralizer EDR killer) to other crews.
- Confidence: High for the activity cluster and financial motivation (corroborated by DOJ indictments/convictions and consistent CrowdStrike, Mandiant, Microsoft, SentinelOne, and Secureworks reporting). Note that the "Carbanak" backdoor has been used by more than one actor, so backdoor-only attributions to FIN7 should be treated with lower confidence than TTP-clustered attributions.
Targeting
- Sectors: Historically heavy on retail, restaurant, hospitality, and gaming (POS-era payment-card theft). Post-2020 ransomware era broadened to software, consulting, financial services, medical equipment/pharmaceutical, cloud services, media, food & beverage, transportation, utilities, manufacturing, legal, and the public sector, plus the automotive industry.
- Regions: Predominantly the United States (the DOJ described theft of card data from 100+ U.S. companies across 47 states), with European victims also reported.
- Victim profile: During POS operations, customer-facing businesses processing large card volumes. In the ransomware/BGH era, victim selection is revenue-driven (targets filtered by company revenue using ZoomInfo) and FIN7 specifically phishes IT staff with elevated administrative privileges to accelerate domain compromise.
Notable campaigns
- 2017 — Restaurant/retail POS theft (Chipotle and others): Large-scale spearphishing of hospitality/restaurant chains delivering Carbanak/HALFBAKED and POS scrapers (e.g., Pillowmint) to harvest payment-card data. (CrowdStrike, Secureworks GOLD NIAGARA)
- 2018 — Saks Fifth Avenue / Lord & Taylor breach: POS compromise of high-end retailers exposing roughly 5 million payment cards sold on darknet markets. (Multiple vendor reporting)
- Aug 1, 2018 — DOJ indictment & arrests: Three Ukrainian nationals (Fedir Hladyr, Dmytro Fedorov, Andrii Kolpakov) charged; the indictment exposed the Combi Security front company used to recruit operators. (CrowdStrike "Arrests Put New Focus on CARBON SPIDER")
- 2020 — Pivot to big game hunting: FIN7 stands up its own RaaS (Darkside, later BlackMatter) and begins deploying ransomware as the end objective. (CrowdStrike "CARBON SPIDER Embraces Big Game Hunting")
- Apr 2021 — Member sentencing: Fedir Hladyr sentenced to 10 years following a 2019 guilty plea. (CrowdStrike / DOJ)
- Oct 2021 — "Bastion Secure" fake-pentest-firm scheme: FIN7 ran a sham security company to hire legitimate penetration testers/IT specialists who unknowingly performed ransomware-intrusion work. (Vendor reporting)
- 2022 — "Checkmarks" automated exploitation platform: FIN7 built an automated attack system mass-exploiting public-facing Microsoft Exchange via ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) with an Auto-SQLi (SQLMap) module; intrusions hit U.S. manufacturing, legal, and public-sector firms (medium-confidence attribution). (SentinelOne "FIN7 Reboot")
- 2022 onward — AvNeutralizer / AuKill EDR-killer: FIN7 developed an EDR-tampering tool (first operational use ~mid-2022; an updated version abuses the Windows
ProcLaunchMon.sys/Process Explorer driver) and sold it on criminal forums; used by Black Basta and later multiple ransomware crews. (SentinelOne, IBM) - Apr 2023 — Return with Cl0p ransomware (Sangria Tempest): Microsoft observed FIN7 use POWERTRASH to load the Lizar post-exploitation tool, then OpenSSH and Impacket for lateral movement before deploying Cl0p ransomware. (Microsoft / The Hacker News)
- Late 2023 (reported Apr 2024) — Automaker IT-staff spearphishing: FIN7 phished privileged IT employees at a large U.S.-based multinational automaker using a typosquatted Advanced IP Scanner site (
advanced-ip-sccanner[.]com→myipscanner[.]com), a Dropbox-hostedWsTaskLoad.exe, POWERTRASH, the Anunak/Carbanak backdoor, and OpenSSH for persistence. (BlackBerry / BleepingComputer)
TTPs by ATT&CK tactic
Initial Access
- T1566.001 — Spearphishing Attachment: Weaponized Microsoft Office documents and RTF files (often DDE-triggered) sent to targeted employees.
- T1566.002 — Spearphishing Link: Phishing emails with malicious / typosquatted links (e.g., fake Advanced IP Scanner download site) redirecting to attacker-controlled hosting (Dropbox).
- T1091 — Replication Through Removable Media: Physically mails BadUSB drives that emulate a keyboard to victims to trigger malware downloads.
- T1190 — Exploit Public-Facing Application: Mass-exploited Microsoft Exchange (ProxyShell, incl. CVE-2021-31207) via the automated "Checkmarks" platform with an Auto-SQLi module.
- T1195.002 — Compromise Software Supply Chain: Trojanized legitimate digital products / software supply chains to gain access.
- T1078.003 — Valid Accounts (Local Accounts): Reused compromised credentials to obtain SYSTEM-level access on Exchange servers.
Execution
- T1204.001 / T1204.002 — User Execution (Malicious Link / Malicious File): Lures victims into clicking links or double-clicking attachments (image lures that execute hidden LNK files; JSS Loader/Harpy delivery).
- T1059.001 — PowerShell: POWERTRASH heavily obfuscated PowerShell reflectively loads PE payloads in memory (Carbanak, Lizar/Diceloader, Core Impact).
- T1059.003 / .005 / .007 — Windows Command Shell / VBScript / JavaScript: cmd.exe, VBS, and JS scripting for on-host tasking; T1059 SQL scripts for victim-machine tasks.
- T1559.002 — Dynamic Data Exchange: Office documents abusing DDE for code execution.
- T1218.005 / .011 — Mshta / Rundll32: mshta.exe runs VBScript; rundll32.exe executes malware DLLs.
- T1047 — Windows Management Instrumentation: WMI used to install malware on targeted systems.
- T1674 — Input Injection: Malicious USBs emulate keystrokes to launch PowerShell downloaders.
- T1620 — Reflective Code Loading: Loads .NET assemblies via
Reflection.Assembly::Load(and in-memory PE loading via POWERTRASH).
Persistence
- T1547.001 — Registry Run Keys / Startup Folder: Run/RunOnce keys and Startup-folder items.
- T1543.003 — Windows Service: Creates new Windows services tied to startup.
- T1053.005 — Scheduled Task: Persistence tasks (e.g., masqueraded "AdobeFlashSync"); also uses OpenSSH for persistence.
- T1546.011 — Application Shimming: Application shim databases for persistence.
- T1569.002 — Service Execution: Starts the SSH service via
sc start sshd.
Privilege Escalation
- T1210 — Exploitation of Remote Services: Exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers.
- T1078.003 / T1543.003 / T1053.005 / T1547.001: Service- and task-based escalation/persistence as above.
Defense Evasion
- T1027.010 / .016 — Command Obfuscation / Junk Code Insertion: Fragmented strings, env-var indirection, stdin, character-replacement, and random junk code.
- T1140 — Deobfuscate/Decode Files or Information:
certutilto decode PowerShell; XOR-deobfuscation routines. - T1553.002 — Code Signing: Carbanak payloads and phishing documents signed with purchased/abused certificates.
- T1562.001 — Impair Defenses (Disable or Modify Tools): AvNeutralizer/AuKill tampers with/kills EDR and AV (kernel-mode abuse of
ProcLaunchMon.sys/ Process Explorer driver). (SentinelOne; mapped to T1562.001) - T1564.001 / .003 — Hidden Files & Directories / Hidden Window:
attrib +hto hide an SSH folder;.txt-concealed PowerShell. - T1036.004 / .005 — Masquerading: Scheduled task named "AdobeFlashSync"; ransomware staged as
sleep.exe; loader masquerades asWsTaskLoad.exe. - T1571 — Non-Standard Port: Port/protocol mismatches on 53/80/443/8080 and firewall openings on TCP 59999 and 9898.
- T1497.002 — Virtualization/Sandbox Evasion (User Activity Based Checks): Payloads detonate only on user interaction (double-click of embedded image).
Credential Access
- T1558.003 — Kerberoasting: PowerShell-driven Kerberoasting for credential access and lateral movement.
- T1003 — OS Credential Dumping: Uses Mimikatz (S0002) to harvest credentials. (ATT&CK software mapping; mapped to T1003)
Discovery
- T1087.002 — Domain Account Discovery: Enumerates domain admins via PowerShell and
csvde.exe. - T1069.002 — Permission Groups (Domain Groups):
net groupto enumerate domain groups. - T1057 — Process Discovery:
tasklist /vvia WsTaskLoad.exe / PowerShell. - T1082 — System Information Discovery:
csvde.exeand WsTaskLoad for host enumeration. - T1033 — System Owner/User Discovery:
cmd.exe /C quserfor active sessions. - T1124 — System Time Discovery:
net timevia PowerShell script. - T1591 / T1591.004 — Gather Victim Org Information / Identify Roles: ZoomInfo to filter targets by revenue and to identify IT staff with elevated admin rights (uses AdFind, S0552, internally).
Lateral Movement
- T1021.001 — RDP: Remote Desktop for lateral movement.
- T1021.004 — SSH: OpenSSH for lateral movement and reverse tunnels.
- T1021.005 — VNC: TightVNC to control compromised hosts.
- Impacket / CrackMapExec (S0488): Used for remote execution/spread in the ransomware era (CrackMapExec is an ATT&CK-listed FIN7 tool).
Collection
- T1005 — Data from Local System: Collects files and sensitive data from compromised hosts.
- T1113 — Screen Capture / T1125 — Video Capture: Screenshots and custom desktop video recording to surveil operators/environments (notably reconnaissance of POS/back-office staff).
Command and Control
- T1071.004 — Application Layer Protocol (DNS): C2 over DNS A, OPT, and TXT records.
- T1008 — Fallback Channels: Harpy backdoor falls back to DNS if HTTP C2 fails.
- T1102.002 — Web Service (Bidirectional): Google Docs, Google Scripts, and Pastebin for C2.
- T1572 — Protocol Tunneling: OpenSSH reverse tunnels for C2/egress.
- T1219 — Remote Access Tools: Abuses Atera RMM to download/run malware.
- T1105 — Ingress Tool Transfer: Pulls additional payloads via PowerShell shellcode stagers.
Exfiltration
- T1567.002 — Exfiltration to Cloud Storage: Stolen data exfiltrated to MEGA file-sharing.
Impact
- T1486 — Data Encrypted for Impact: Deploys ransomware as the end objective, including Darkside encrypting ESXi virtual-disk volumes; affiliate deployment of Cl0p, Black Basta, REvil, etc.
Signature tooling & malware
- Carbanak / Anunak (S0030) — custom flagship backdoor; full-featured RAT for control, recon, and POS data theft.
- POWERTRASH (a.k.a. Powertrash) — custom heavily obfuscated PowerShell loader that reflectively loads PE payloads in memory (a strong FIN7 fingerprint; ~50 samples tracked 2020–2022).
- Lizar / Diceloader / IceBot (S0681) — custom modular post-exploitation backdoor / loader.
- JSS Loader (S0648) — custom .NET/JS-based loader for follow-on payloads.
- GRIFFON (S0417) — custom JavaScript-based modular implant/recon backdoor.
- HALFBAKED (S0151), POWERSOURCE/DNSMessenger (S0145), TEXTMATE (S0146), SQLRat (S0390) — custom loaders/backdoors from the spearphishing/POS era.
- BOOSTWRITE (S0415) / RDFSNIFFER (S0416) — custom; BOOSTWRITE is a DLL-hijack loader, RDFSNIFFER tampers with the Aloha Command Center RDP client (POS targeting).
- Pillowmint (S0517) — custom POS RAM-scraper for payment-card data.
- AvNeutralizer / AuKill — custom EDR/AV-killer (kernel driver abuse) marketed/sold on criminal forums.
- Cobalt Strike (S0154), PowerSploit (S0194), Mimikatz (S0002), AdFind (S0552), CrackMapExec (S0488), Core Impact, Impacket, OpenSSH, TightVNC, Atera RMM — public / commercial / cracked offensive and dual-use tooling.
- Ransomware payloads: Darkside / BlackMatter (own RaaS); affiliate use of Maze (S0449), REvil (S0496), Cl0p, Black Basta, ALPHV/BlackCat, LockBit; SystemBC (S9001) as a proxy/loader.
Emulation guidance (Decepticon)
Authorized use only: Execute these emulation steps strictly inside the agreed engagement scope and rules of engagement, with written authorization, against in-scope assets only — never against third parties or production data you are not cleared to touch. Use benign substitutes for destructive impact actions.
Map FIN7's signature chain to Decepticon's own capabilities:
- Initial access (phishing IT staff) — T1566.001/.002, T1204, T1583.001: Use Decepticon's phishing/social-engineering workflow to stand up a typosquatted "IT tool" landing page (mimic Advanced IP Scanner) and deliver a benign tracked payload via a cloud-share link (Dropbox-style). Prioritize recipients with admin rights, mirroring FIN7's IT-staff focus. Stage decoy infra via the cloud skills (look-alike domain + object-storage hosting, T1583.006/T1608.001).
- BadUSB drop — T1091/T1674: If physical-access testing is in scope, emulate the mailed-USB vector with a HID/keystroke-injection device that triggers a benign PowerShell beacon download. Otherwise document the vector without execution.
- Loader & in-memory execution — T1059.001/T1620/T1027: Use the bash/PowerShell tooling plus the defense-evasion skill to reproduce a POWERTRASH-style obfuscated reflective PE loader (string fragmentation, junk code, in-memory load) delivering your C2 stage — do not drop a payload to disk.
- C2 — T1071.004/T1102.002/T1572/T1219: Drive C2 through the c2/sliver skill. Emulate FIN7's channel diversity: an HTTP(S) Sliver listener, a DNS listener (mirrors T1071.004), web-service C2 (mirror T1102.002), with OpenSSH reverse-tunnel egress (T1572) and an RMM-style channel as a fallback. Configure non-standard ports (T1571) to test egress controls.
- Discovery & cred access — T1087.002/T1069.002/T1558.003/T1003: Use the Active Directory skills to enumerate domain admins/groups (
net group, csvde-equivalent), then perform Kerberoasting and credential extraction (Mimikatz-equivalent via the AD/cred-access tooling) exactly as FIN7 chains recon → Kerberoast → lateral movement. - Lateral movement — T1021.001/.004/.005/T1572: Use the lateral-movement skill for RDP, SSH, VNC, and Impacket/CrackMapExec-style remote execution to traverse to high-value hosts (Exchange, hypervisors, file servers).
- Defense evasion / EDR tampering — T1562.001/T1553.002: With the defense-evasion skill, emulate AvNeutralizer-style EDR-tamper detection testing (e.g., attempt to stop/blind the agreed test sensor in a controlled VM) and code-signing/masquerading of artifacts — never disable production security controls outside an isolated test host.
- Exchange/ProxyShell + Auto-SQLi — T1190/T1195.002: If web-facing assets are in scope, emulate the "Checkmarks" pattern with the cloud/web-exploitation tooling (ProxyShell-class checks, SQLi probing) against the designated test target only.
- Impact (ransomware) — T1486: Do not encrypt real data. Emulate the BGH end-state with a benign canary "ransom" routine (touch marker files / rename in an isolated directory) and stage a simulated exfil-then-encrypt to MEGA-like storage (T1567.002) to exercise blue-cell DLP and backup detection.
Detection & defense
- Phishing of privileged IT staff (T1566/T1204): Detect typosquatted domains impersonating admin tools (Advanced IP Scanner, etc.); alert on cloud-share downloads of EXE/MSI by IT-admin accounts; block/inspect newly registered look-alike domains; enforce mark-of-the-web and macro/DDE disablement on Office.
- BadUSB / HID injection (T1091/T1674): Enforce USB device-control policy; alert on a "keyboard" enumerating immediately followed by PowerShell network egress.
- POWERTRASH / in-memory loaders (T1059.001/T1620/T1027): Enable PowerShell Script Block Logging, AMSI, and Module Logging; alert on reflective
Assembly::Load/ in-memory PE patterns,certutildecoding, and heavily obfuscated/fragmented script content. - Persistence (T1547.001/T1543.003/T1053.005/T1569.002): Monitor new Run keys, new services, scheduled tasks with masquerading names ("AdobeFlashSync"), and
sc start sshd/ unexpectedsshdservices on Windows. - Lateral movement & cred access (T1021/T1558.003/T1003): Alert on Kerberoast TGS-REQ bursts (RC4), LSASS access, Impacket/CrackMapExec patterns, and anomalous RDP/SSH/VNC between workstations and servers; deploy honey SPNs.
- C2 (T1071.004/T1102.002/T1572/T1219): Inspect/limit outbound DNS (large TXT/OPT volume), monitor for SSH reverse tunnels from non-admin hosts, baseline use of Google Docs/Scripts/Pastebin and Atera/other RMM agents; block unsanctioned RMM.
- EDR tampering (T1562.001): Enable tamper protection; monitor for vulnerable-driver loads (e.g.,
ProcLaunchMon.sys, Process Explorer driver) and BYOVD patterns; alert on security-service stop/kill events. - Exploitation (T1190/T1210): Patch Exchange ProxyShell (CVE-2021-34473/-34523/-31207) and ZeroLogon (CVE-2020-1472); monitor Exchange for webshell drops and Auto-SQLi/SQLMap signatures.
- Impact (T1486/T1567.002): Protect/segment ESXi management; immutable, offline backups; DLP and egress monitoring for MEGA/cloud-storage bulk uploads; alert on mass-rename/encryption file events.
Sources
- MITRE ATT&CK — FIN7 (G0046): https://attack.mitre.org/groups/G0046/
- CrowdStrike — "Arrests Put New Focus on CARBON SPIDER Adversary Group": https://www.crowdstrike.com/en-us/blog/arrests-put-new-focus-on-carbon-spider-adversary-group/
- CrowdStrike — "CARBON SPIDER Embraces Big Game Hunting, Part 2": https://www.crowdstrike.com/en-us/blog/carbon-spider-embraces-big-game-hunting-part-2/
- SentinelOne — "FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks": https://www.sentinelone.com/labs/fin7-reboot-cybercrime-gang-enhances-ops-with-new-edr-bypasses-and-automated-attacks/
- The Hacker News — "Notorious Cyber Gang FIN7 Returns With Cl0p Ransomware": https://thehackernews.com/2023/05/notorious-cyber-gang-fin7-returns-cl0p.html
- BleepingComputer — "FIN7 targets American automaker's IT staff in phishing attacks": https://www.bleepingcomputer.com/news/security/fin7-targets-american-automakers-it-staff-in-phishing-attacks/
- IBM — "Hacker group FIN7 is selling EDR evasion tools to other cyber criminals": https://www.ibm.com/think/news/hacker-group-fin7-selling-edr-evasion-tools-other-cyber-criminals
- Secureworks — "GOLD NIAGARA Threat Profile": https://www.secureworks.com/research/threat-profiles/gold-niagara