Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareHALFBAKED | HALFBAKED can use WMI queries to gather system information. |
| T1053.005 Scheduled Task |
GroupFIN7 | FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence. |
| T1057 Process Discovery |
MalwareHALFBAKED | HALFBAKED can obtain information about running processes on the victim. |
| T1059.001 PowerShell |
GroupFIN7 | FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH. |
| T1059.001 PowerShell |
MalwareHALFBAKED | HALFBAKED can execute PowerShell scripts. |
| T1070.004 File Deletion |
MalwareHALFBAKED | HALFBAKED can delete a specified file. |
| T1082 System Information Discovery |
MalwareHALFBAKED | HALFBAKED can obtain information about the OS, processor, and BIOS. |
| T1105 Ingress Tool Transfer |
GroupFIN7 | FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload. |
| T1113 Screen Capture |
MalwareHALFBAKED | HALFBAKED can obtain screenshots from the victim. |
| T1204.002 Malicious File |
GroupFIN7 | FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor. |
| T1218.005 Mshta |
GroupFIN7 | FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems. |
| T1497.002 User Activity Based Checks |
GroupFIN7 | FIN7 used images embedded into document lures that only activate the payload when a user double clicks to avoid sandboxes. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN7 | FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder. |
| T1566.001 Spearphishing Attachment |
GroupFIN7 | FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.