LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.CitationFireEye FIN7 March 2017CitationFireEye FIN7 April 2017CitationFireEye CARBANAK June 2017CitationFireEye FIN7 Aug 2018CitationCrowdStrike Carbon Spider August 2021CitationMandiant FIN7 Apr 2022CitationBiZone Lizar May 2021

EnterpriseG0046GroupObject v4.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

FIN7 matters because MITRE describes it as a financially motivated group with a long operating history, broad U.S. industry targeting, prior point-of-sale malware use, and a shift since 2020 toward big-game hunting and ransomware activity. For leaders, the decision point is not whether FIN7 is “in the environment,” but whether defenses can withstand the behaviors associated with the group: credential theft, remote access tooling, lateral movement over RDP/SSH, Active Directory discovery, PowerShell backdoors, command-and-control resilience, data collection, and ransomware-stage disruption.

Executive priority

Treat FIN7 as a resilience and readiness benchmark for financially motivated intrusion chains. Organizations in retail, hospitality, financial services, healthcare-related equipment, cloud services, transportation, pharmaceutical, utilities, and other listed sectors should ask whether identity controls, endpoint visibility, POS/system segmentation, ransomware recovery, and incident response evidence are strong enough to support fast decisions during a financially motivated intrusion. Budget priority should favor controls that reduce credential abuse, remote access exposure, uncontrolled scripting, and ransomware blast radius.

Technical view

MITRE provides no group-level detection text and no group-level platforms or tactics, so validation should be driven by the documented relationships. Related software includes Mimikatz, Carbanak, POWERSOURCE, TEXTMATE, HALFBAKED, Cobalt Strike, PowerSploit, SQLRat, BOOSTWRITE, RDFSNIFFER, GRIFFON, Maze, CrackMapExec, REvil, Pillowmint, AdFind, JSS Loader, Lizar, and SystemBC. Related techniques include local data collection, fallback command-and-control channels, RDP lateral movement, and SSH lateral movement. SOC and IR teams should verify visibility across Windows-heavy endpoint activity, PowerShell and script execution, credential access indicators, Active Directory enumeration, remote access sessions, database or SQL-script abuse where relevant, POS environments where present, network C2/proxy behavior, and ransomware precursor activity.

Likely telemetry

  • Endpoint process creation, command-line, module load, DLL search-order, and persistence-related events on Windows systems
  • PowerShell, script block, VBS, macro-enabled document handling, and memory-resident backdoor indicators where logging is enabled
  • Authentication logs for Windows accounts, privileged accounts, RDP sessions, and SSH sessions on Linux, macOS, ESXi, or network-adjacent systems where applicable
  • Active Directory query and enumeration evidence, including command-line tooling consistent with directory discovery
  • Credential access telemetry relevant to tools such as Mimikatz and post-exploitation frameworks

Detection direction

  • Because MITRE does not provide official detection guidance for this group object, map detections to the related software and techniques rather than relying on the group name alone.
  • Validate coverage for credential dumping, Active Directory enumeration, remote access tool use, PowerShell-based backdoors, commercial/offensive security frameworks, and ransomware precursor behaviors.
  • Tune detections to distinguish authorized administration and penetration testing tools from suspicious use; several related tools have legitimate security or administrative uses, including Cobalt Strike, PowerSploit, CrackMapExec, and AdFind.
  • Correlate RDP/SSH logons with account context, source geography/network zone, device role, privilege level, and follow-on execution rather than alerting on protocol use alone.
  • Review blind spots in POS networks, database servers, remote IT management paths, unmanaged endpoints, cloud-hosted workloads, and systems where PowerShell or endpoint logging is limited.

Mitigation priorities

  • Prioritize identity hardening: privileged account reduction, strong authentication for remote access, credential hygiene, and monitoring for credential dumping and abnormal account use.
  • Reduce remote access risk by limiting RDP and SSH exposure, enforcing administrative access paths, and monitoring interactive logons to sensitive systems.
  • Harden endpoints against unauthorized scripting, macro/VBS abuse, suspicious PowerShell behavior, DLL search-order abuse, and unapproved post-exploitation tooling.
  • Segment and monitor POS, payment, server, backup, and high-value business systems to limit lateral movement and ransomware blast radius.
  • Maintain tested incident response and ransomware recovery procedures, including offline or protected backups and evidence collection plans for endpoint, identity, network, and data access telemetry.
Additional notes and limits

The most useful defensive value of this object is as a threat-informed control validation profile. FIN7 is associated in ATT&CK with financially motivated activity, broad industry targeting, point-of-sale malware, remote access and post-exploitation tooling, credential theft, lateral movement, data collection, and ransomware families including REvil and Maze. The Carbanak linkage is explicitly qualified by MITRE: multiple groups have used Carbanak, so defenders should avoid over-attributing based on that malware alone.

Official group-level detection, tactics, and platforms are not provided in the supplied object. Platform and behavior guidance here is inferred only from the supplied relationship context and related software/technique descriptions. Local relevance depends on the organization’s sector, POS footprint, Windows/Linux/macOS/ESXi exposure, remote access architecture, logging maturity, and whether named dual-use tools are authorized in the environment.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.CitationFireEye FIN7 March 2017CitationFireEye FIN7 April 2017CitationFireEye CARBANAK June 2017CitationFireEye FIN7 Aug 2018CitationCrowdStrike Carbon Spider August 2021CitationMandiant FIN7 Apr 2022CitationBiZone Lizar May 2021

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
4.1
Created
Modified
Raw hash
9de71303cbad1630...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.