Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0046
MITRE ATT&CK Group

FIN7 (G0046)

GOLD NIAGARAITG14Carbon SpiderELBRUSSangria Tempest
ShareXLinkedInRedditHN

[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of [FIN7](https://attack.mitre.org/groups/G0046) was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, [FIN7](https://attack.mitre.org/groups/G0046) shifted operations to big game hunting (BGH), including use of [REvil](https://attack.mitre.org/software/S0496) ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the [Carbanak](https://attack.mitre.org/groups/G0008) Group, but multiple threat groups have been observed using [Carbanak](https://attack.mitre.org/software/S0030), leading these groups to be tracked separately.(Citation: FireEye FIN7 March 2017)(Citation: FireEye FIN7 April 2017)(Citation: FireEye CARBANAK June 2017)(Citation: FireEye FIN7 Aug 2018)(Citation: CrowdStrike Carbon Spider August 2021)(Citation: Mandiant FIN7 Apr 2022)(Citation: BiZone Lizar May 2021)

▪Techniques used (67)

T1204.001Malicious LinkT1553.002Code SigningT1078Valid AccountsT1059Command and Scripting InterpreterT1021.004SSHT1190Exploit Public-Facing ApplicationT1027.016Junk Code InsertionT1608.005Link TargetT1033System Owner/User DiscoveryT1053.005Scheduled TaskT1021.005VNCT1036.005Match Legitimate Resource Name or LocationT1564.003Hidden WindowT1566.002Spearphishing LinkT1036.004Masquerade Task or ServiceT1218.011Rundll32T1047Windows Management InstrumentationT1620Reflective Code LoadingT1059.005Visual BasicT1219Remote Access ToolsT1564.001Hidden Files and DirectoriesT1059.001PowerShellT1572Protocol TunnelingT1546.011Application ShimmingT1559.002Dynamic Data ExchangeT1069.002Domain GroupsT1021.001Remote Desktop ProtocolT1674Input InjectionT1486Data Encrypted for ImpactT1588.002ToolT1591Gather Victim Org InformationT1569.002Service ExecutionT1583.006Web ServicesT1497.002User Activity Based ChecksT1059.007JavaScriptT1547.001Registry Run Keys / Startup FolderT1608.004Drive-by TargetT1686Disable or Modify System FirewallT1082System Information DiscoveryT1125Video CaptureT1571Non-Standard PortT1140Deobfuscate/Decode Files or InformationT1027.010Command ObfuscationT1087.002Domain AccountT1204.002Malicious FileT1057Process DiscoveryT1218.005MshtaT1102.002Bidirectional CommunicationT1105Ingress Tool TransferT1078.003Local AccountsT1591.004Identify RolesT1124System Time DiscoveryT1583.001DomainsT1005Data from Local SystemT1543.003Windows ServiceT1091Replication Through Removable MediaT1071.004DNST1059.003Windows Command ShellT1566.001Spearphishing AttachmentT1608.001Upload MalwareT1008Fallback ChannelsT1558.003KerberoastingT1195.002Compromise Software Supply ChainT1113Screen CaptureT1567.002Exfiltration to Cloud StorageT1210Exploitation of Remote ServicesT1587.001Malware

▪Software used (19)

S0417GRIFFONmalwareS0002MimikatztoolS0552AdFindtoolS0648JSS LoadermalwareS0151HALFBAKEDmalwareS0496REvilmalwareS0194PowerSploittoolS0488CrackMapExectoolS0030CarbanakmalwareS0517PillowmintmalwareS0154Cobalt StrikemalwareS0449MazemalwareS0145POWERSOURCEmalwareS0416RDFSNIFFERmalwareS0390SQLRatmalwareS0681LizarmalwareS0146TEXTMATEmalwareS0415BOOSTWRITEmalwareS9001SystemBCmalware
G0046on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.