PULSE NAME
Fin7 Unveiled: A deep dive into notorious cybercrime gang
WHITE FIN7 AlienVault 2022-12-23 Modified: 2022-12-23
254
IOCs
HIGH VOLUME
The highly active threat group FIN7 has been continuously broadening their cybercrime horizons and recently added ransomware to its attack arsenal. FIN7 group is known to hold a notorious status due to their achievement in deploying extensive backdoors in leveraging software supply chains, distributing malicious USB sticks, and cooperating with other groups. PTI team obtained visibility into the inner workings of the FIN7 threat group and managed to gain information about their organizational structures, identities, attack vectors, infrastructures, proof-supported affiliations with other ransomware groups (such as DarkSide, who were behind the Colonial Pipeline attack in 2021), victim targeting, and other relevant observations. All of the findings are supported by translated conversations among the members of FIN7, including screenshots of their infrastructures.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (6 / 254 total)
All FileHash-SHA256 FileHash-MD5 FileHash-SHA1 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a04dfae8271de627a07ea2b60dc8e381 MD5 of 0d43eca3777f98773314e04870bcbe76d6c5eb0694356509cd9f698d9a169f76 2022-12-23
FileHash-MD5 828a5d8bc4ff9eb951291593f785f01e MD5 of 8d8d2ef56247e8425da9c1c71466befeb918cdd2b1eedefa16b539abc9ff2cce 2022-12-23
FileHash-MD5 b379eb02974d8c70b92314ac5a86e8f5 MD5 of dc9442838b464e96281a32705c9b5958e4f45dbefd1ef4a885fac9898af0a4b7 2022-12-23
FileHash-MD5 7ba2606a5d6de4768f0608c644bdb764 MD5 of 5ccf66192ea9d2b6395fbb4a058d0af8409040d6d38b82b7fa1bf120371e9538 2022-12-23
FileHash-MD5 ad27e09917b51e8436da8e72b0c515eb MD5 of 6e8e2aaa62ec3d3605eef11a2a28b73fa6769eae49d86dc872676b36ccf6aee7 2022-12-23
FileHash-MD5 7b6e38b44130e1cc0e431dc2eafcb4a5 MD5 of 0f083aac77fb734a8e81fb9dff218f0414ac6c4c9a23b2832837fbc2c7e2031d 2022-12-23