ATT&CKReferencesFireEye FIN7 April 2017

FireEye FIN7 April 2017

Carr, N., et al. (2017, April 24). FIN7 Evolution and the Phishing LNK. Retrieved April 24, 2017.

Open the source

Techniques2

Groups2

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareHALFBAKED

HALFBAKED can use WMI queries to gather system information.

T1053.005
Scheduled Task
GroupFIN7

FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence.

T1057
Process Discovery
MalwareHALFBAKED

HALFBAKED can obtain information about running processes on the victim.

T1059.001
PowerShell
GroupFIN7

FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH.

T1059.001
PowerShell
MalwareHALFBAKED

HALFBAKED can execute PowerShell scripts.

T1070.004
File Deletion
MalwareHALFBAKED

HALFBAKED can delete a specified file.

T1082
System Information Discovery
MalwareHALFBAKED

HALFBAKED can obtain information about the OS, processor, and BIOS.

T1105
Ingress Tool Transfer
GroupFIN7

FIN7 has downloaded additional malware to execute on the victim's machine, including by using a PowerShell script to launch shellcode that retrieves an additional payload.

T1113
Screen Capture
MalwareHALFBAKED

HALFBAKED can obtain screenshots from the victim.

T1204.002
Malicious File
GroupFIN7

FIN7 lured victims to double-click on images in the attachments they sent which would then execute the hidden LNK file. Additionally, FIN7 has used malicious Microsoft Word and Excel files and Leo VBS to distribute an updated version of JSS Loader and to distribute the Harpy backdoor.

T1218.005
Mshta
GroupFIN7

FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.

T1497.002
User Activity Based Checks
GroupFIN7

FIN7 used images embedded into document lures that only activate the payload when a user double clicks to avoid sandboxes.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN7

FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.

T1566.001
Spearphishing Attachment
GroupFIN7

FIN7 sent spearphishing emails with either malicious Microsoft Documents or RTF files attached.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.