FIN7__2019__Mahalo_FIN7.pdf
ID: 4c5186b0-d6f4-4c13-a81c-d2957af14db6
STIX ID: report--4c5186b0-d6f4-4c13-a81c-d2957af14db6
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2019-10-11
Last Modified Date: 2019-10-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye/Mandiant describes FIN7’s newly observed tools: BOOSTWRITE, an in-memory DLL-search-order loader that retrieves decryption keys from a remote server and loads encrypted payloads (including CARBANAK), and RDFSNIFFER, a payload that hooks Win32 APIs to tamper with or hijack NCR Aloha Command Center Client sessions (allowing file upload/download, execute, and deletion). The blog details technical behaviors, code-signing evasions (signed sample with anomalous timestamps), sample hashes/C2s, Yara hunting ideas, MITRE ATT&CK mappings, and recommended detection approaches.
