FlagThis
← Threat Actors
/
Russia
/
FIN7
DOSSIER // FIN7
FIN7
▲ High Threat
Russia
Primary Aliases:
CARBON SPIDER
Sangria Tempest
ATK32
Calcium
🔍 Adversary Rosetta Stone (12) ▾
📋 Copy All
Sponsor / State Affiliation
Independent / Not Attributed
Primary Motivation
Financial Theft, Cybercrime
Active Timeline
Unknown – Present
Confidence Rating
70% (Grounded)
Groups targeting financial organizations or people with significant financial assets.
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🛡️ MITRE ATT&CK (G0046) ↗
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(2)
CVE-2017-11882
Weaponized Vulnerability
CVSS 8.5
KEV
EPSS 85.0%
CVE-2018-0802
Weaponized Vulnerability
CVSS 8.5
KEV
EPSS 85.0%
📋 Copy CSV
Tenable Nessus
Qualys / Wiz
🎯 Target Sectors & Focus
Retail
Hospitality
Restaurant
Financial
🛡️ MITRE ATT&CK® Attack Lifecycle
(67 TTPs)
📥 Download Navigator JSON
All Stages
67
Initial Access
6
Execution
5
Persistence & Privilege Escalation
1
Defense Evasion
2
Credential Access & Discovery
4
Lateral Movement & Collection
2
Command & Control
3
Exfiltration & Impact
1
Operational Techniques
43
Initial Access
6
T1566
Valid Accounts
↗
T1566
Exploit Public-Facing Application
↗
T1566
Spearphishing Link
↗
T1566
Drive-by Target
↗
T1566
Spearphishing Attachment
↗
T1566
Compromise Software Supply Chain
↗
Execution
5
T1059
Command and Scripting Interpreter
↗
T1059
Scheduled Task
↗
T1059
PowerShell
↗
T1059
Service Execution
↗
T1059
Windows Command Shell
↗
Persistence & Privilege Escalation
1
T1547
Registry Run Keys / Startup Folder
↗
Defense Evasion
2
T1027
Code Signing
↗
T1027
Command Obfuscation
↗
Credential Access & Discovery
4
T1003
System Owner/User Discovery
↗
T1003
System Information Discovery
↗
T1003
Process Discovery
↗
T1003
System Time Discovery
↗
Lateral Movement & Collection
2
T1021
Remote Desktop Protocol
↗
T1021
Screen Capture
↗
Command & Control
3
T1071
Remote Access Tools
↗
T1071
Ingress Tool Transfer
↗
T1071
Exfiltration to Cloud Storage
↗
Exfiltration & Impact
1
T1485
Data Encrypted for Impact
↗
Operational Techniques
43
T1000
Malicious Link
↗
T1000
SSH
↗
T1000
Junk Code Insertion
↗
T1000
Link Target
↗
T1000
VNC
↗
T1000
Match Legitimate Resource Name or Location
↗
T1000
Hidden Window
↗
T1000
Masquerade Task or Service
↗
T1000
Rundll32
↗
T1000
Windows Management Instrumentation
↗
T1000
Reflective Code Loading
↗
T1000
Visual Basic
↗
T1000
Hidden Files and Directories
↗
T1000
Protocol Tunneling
↗
T1000
Application Shimming
↗
T1000
Dynamic Data Exchange
↗
T1000
Domain Groups
↗
T1000
Input Injection
↗
T1000
Tool
↗
T1000
Gather Victim Org Information
↗
T1000
Web Services
↗
T1000
User Activity Based Checks
↗
T1000
JavaScript
↗
T1000
Disable or Modify System Firewall
↗
T1000
Video Capture
↗
T1000
Non-Standard Port
↗
T1000
Deobfuscate/Decode Files or Information
↗
T1000
Domain Account
↗
T1000
Malicious File
↗
T1000
Mshta
↗
T1000
Bidirectional Communication
↗
T1000
Local Accounts
↗
T1000
Identify Roles
↗
T1000
Domains
↗
T1000
Data from Local System
↗
T1000
Windows Service
↗
T1000
Replication Through Removable Media
↗
T1000
DNS
↗
T1000
Upload Malware
↗
T1000
Fallback Channels
↗
T1000
Kerberoasting
↗
T1000
Exploitation of Remote Services
↗
T1000
Malware
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Adversary Rosetta Stone // FIN7
×
🪟 Microsoft Threat Actor Naming
Sangria Tempest
📋
🦅 CrowdStrike Monikers
CARBON SPIDER
📋
🛡️ Other Industry Tracking Codes
ATK32
📋
Calcium
📋
Carbanak
📋
Coreid
📋
ELBRUS
📋
G0008
📋
G0046
📋
GOLD NIAGARA
📋
ITG14
📋
JokerStash
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD