EXPLORE
← Back to Actors

FIN7

FIN7GOLD NIAGARAITG14Carbon SpiderELBRUSSangria Tempest

[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of [FIN7](https://attack.mitre.org/groups/G0046) was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, [FIN7](https:/...

68
Techniques
62
Covered
6
Gaps
91%
Coverage
Coverage62/68

COVERED (62)

T1005Data from Local System51 det.T1008Fallback Channels5 det.T1021.001Remote Desktop Protocol54 det.T1021.004SSH35 det.T1021.005VNC2 det.T1027.010Command Obfuscation38 det.T1033System Owner/User Discovery62 det.T1036.004Masquerade Task or Service7 det.T1036.005Match Legitimate Resource Name or Location45 det.T1047Windows Management Instrumentation88 det.T1053.005Scheduled Task100 det.T1057Process Discovery23 det.T1059Command and Scripting Interpreter532 det.T1059.001PowerShell376 det.T1059.003Windows Command Shell87 det.T1059.005Visual Basic70 det.T1059.007JavaScript64 det.T1069.002Domain Groups45 det.T1071.004DNS36 det.T1078Valid Accounts306 det.T1078.003Local Accounts23 det.T1082System Information Discovery88 det.T1087.002Domain Account58 det.T1091Replication Through Removable Media8 det.T1102.002Bidirectional Communication16 det.T1105Ingress Tool Transfer191 det.T1113Screen Capture19 det.T1124System Time Discovery4 det.T1125Video Capture3 det.T1140Deobfuscate/Decode Files or Information58 det.T1190Exploit Public-Facing Application233 det.T1195.002Compromise Software Supply Chain24 det.T1204.001Malicious Link11 det.T1204.002Malicious File461 det.T1210Exploitation of Remote Services37 det.T1218.005Mshta49 det.T1218.011Rundll3276 det.T1219Remote Access Tools46 det.T1486Data Encrypted for Impact394 det.T1543.003Windows Service80 det.T1546.011Application Shimming11 det.T1547.001Registry Run Keys / Startup Folder53 det.T1553.002Code Signing4 det.T1558.003Kerberoasting35 det.T1559.002Dynamic Data Exchange1 det.T1562.004Disable or Modify System Firewall48 det.T1564.001Hidden Files and Directories25 det.T1564.003Hidden Window11 det.T1566.001Spearphishing Attachment1055 det.T1566.002Spearphishing Link1086 det.T1567.002Exfiltration to Cloud Storage31 det.T1569.002Service Execution65 det.T1571Non-Standard Port17 det.T1572Protocol Tunneling61 det.T1583.001Domains68 det.T1583.006Web Services1 det.T1587.001Malware10 det.T1588.002Tool13 det.T1591.004Identify Roles2 det.T1608.001Upload Malware3 det.T1620Reflective Code Loading16 det.T1686Disable or Modify System Firewall19 det.