The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN7 | FIN7 has attempted to run Darkside ransomware with the filename sleep.exe. Additionally, FIN7 has mimicked WsTaskLoad.exe, which is associated with the Wondershare software suite, by using a malicious executable under the same name. |
| T1053.005 Scheduled Task |
GroupFIN7 | FIN7 malware has created scheduled tasks to establish persistence. Specifically, FIN7 has used OpenSSH to establish persistence. |
| T1057 Process Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery. |
| T1059.001 PowerShell |
GroupFIN7 | FIN7 used a PowerShell script to launch shellcode that retrieved an additional payload. Additionally, FIN7 has executed a custom obfuscation of the shellcode invoker in PowerSploit called POWERTRASH. |
| T1069.002 Domain Groups |
GroupFIN7 | FIN7 has used the command `net group "domain admins" /domain` to enumerate domain groups. |
| T1082 System Information Discovery |
GroupFIN7 | FIN7 has used csvde.exe, which is a built-in Windows command line tool, to export system information. Additionally, WsTaskLoad has gathered system information, such as operating system and hostname. |
| T1087.002 Domain Account |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information. |
| T1124 System Time Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to execute `net time`. |
| T1486 Data Encrypted for Impact |
GroupFIN7 | FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting. |
| T1564.001 Hidden Files and Directories |
GroupFIN7 | FIN7 has used `attrib +h “C:\ProgramData\ssh”` to make the SSH folder hidden. |
| T1566.002 Spearphishing Link |
GroupFIN7 | FIN7 has conducted broad phishing campaigns using malicious links. Additionally, FIN7 has sent spearphishing emails containing a typosquatted link to “ip-sccanner[.]com.” |
| T1569.002 Service Execution |
GroupFIN7 | FIN7 has started the SSH service by executing `sc start sshd`. |
| T1571 Non-Standard Port |
GroupFIN7 | FIN7 has used port-protocol mismatches on ports such as 53, 80, 443, and 8080 during C2. FIN7 has used TCP ports 59999 and 9898 for firewall rules. |
| T1572 Protocol Tunneling |
GroupFIN7 | FIN7 has tunneled C2 traffic via OpenSSH. |
| T1583.001 Domains |
GroupFIN7 | FIN7 has registered look-alike domains for use in phishing campaigns. Additionally, FIN7 has registered a malicious domain as `advanced-ip-sccanner[.]com` that redirected to an adversary-controlled Dropbox which contained the malicious executable. |
| T1591.004 Identify Roles |
GroupFIN7 | FIN7 has identified IT staff and employees who had higher levels of administrative rights. |
| T1608.005 Link Target |
GroupFIN7 | FIN7 has created a fake link that redirected to an adversary-controlled Dropbox that downloaded the malicious executable. |
| T1686 Disable or Modify System Firewall |
GroupFIN7 | FIN7 has added a firewall rule to allow TCP port 59999 inbound and a rule to allow sshd.exe on TCP port 9898. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.