PULSE NAME
FIN7: Silent Push unearths 4000+ phishing and shell domains
WHITE FIN7 AlienVault 2024-07-11 Modified: 2024-08-10
91
IOCs
HIGH VOLUME
Silent Push threat analysts have uncovered an extensive series of campaigns linked to the FIN7 cybercrime group, including several hundred active phishing, spoofing, shell and malware delivery domains and IPs targeting various organizations. The campaigns utilize over 4000 domains and subdomains, with nearly half active in the past week. Prominent global brands like Louvre Museum, Meta, Reuters, Microsoft, and others have been targeted. The group employs tactics like spearphishing, malware distribution, and renting infrastructure from bulletproof hosting providers.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Carbanak - S0030 Anunak Gracewire EugenLoader
Indicators of Compromise (1 / 91 total)
All FileHash-MD5 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 ff25441b7631d64afefdb818cfcceec7 2024-07-11