ATT&CKReferencesFireEye FIN7 Aug 2018

FireEye FIN7 Aug 2018

Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupFIN7

FIN7 has used fragmented strings, environment variables, standard input (stdin), and native character-replacement functionalities to obfuscate commands.

T1053.005
Scheduled Task
GroupFIN7

FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence.

T1059
Command and Scripting Interpreter
GroupFIN7

FIN7 used SQL scripts to help perform tasks on the victim's machine.

T1059.003
Windows Command Shell
GroupFIN7

FIN7 used the command prompt to launch commands on the victim’s machine. Additionally, FIN7 has used cmd.exe to open the Run dialog by sending the “Windows + R” keys through malicious USBs acting as virtual keyboards.

T1059.005
Visual Basic
GroupFIN7

FIN7 used VBS scripts to help perform tasks on the victim's machine.

T1059.007
JavaScript
GroupFIN7

FIN7 used JavaScript scripts to help perform tasks on the victim's machine.

T1071.004
DNS
GroupFIN7

FIN7 has performed C2 using DNS via A, OPT, and TXT records.

T1102.002
Bidirectional Communication
GroupFIN7

FIN7 used legitimate services like Google Docs, Google Scripts, and Pastebin for C2.

T1125
Video Capture
GroupFIN7

FIN7 created a custom video recording capability that could be used to monitor operations in the victim's environment.

T1543.003
Windows Service
GroupFIN7

FIN7 created new Windows services and added them to the startup directories for persistence.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN7

FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.

T1553.002
Code Signing
GroupFIN7

FIN7 has signed Carbanak payloads with legally purchased code signing certificates. FIN7 has also digitally signed their phishing documents, backdoors and other staging tools to bypass security controls.

T1571
Non-Standard Port
GroupFIN7

FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.