ThreatBox · Threat Actor Attribution
FIN7
a.k.a. Carbanak, Carbon Spider, ITG14
Financial Ukraine / Russia (mixed attribution) First seen 2013
FIN7 is a financially motivated cybercrime group primarily targeting the retail and hospitality industries via point-of-sale malware and spearphishing. They pioneered the Carbanak banking-trojan platform. Despite arrests of leadership in 2018, the group has continued operations with new campaigns using Carbanak, GRIFFON, and BADUSB variants.
Targeted sectors
RetailHospitalityRestaurantPoint-of-Sale systems
Targeted regions
North AmericaEurope
Known TTPs (4)
T1566.002Spearphishing Link
T1059.003Windows Command Shell
T1005Data from Local System
T1041Exfiltration Over C2 Channel
Click any technique to open the MITRE ATT&CK reference.
Attack Timeline
- 2013-12Carbanak trojan first observed
- 2018-083 senior members arrested in Europe
- 2020-07BADUSB campaign — mailing malicious USB drives to victims
- 2023-11Return with 'AvNeutralizer' EDR-killer tool
References
End of dossier · FIN7
Back to ThreatBox