logo

FIN7__2019__Mahalo_FIN7.pdf

ID: 4c5186b0-d6f4-4c13-a81c-d2957af14db6

STIX ID: report--4c5186b0-d6f4-4c13-a81c-d2957af14db6

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2019-10-11

Last Modified Date: 2019-10-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye/Mandiant describes FIN7’s newly observed tools: BOOSTWRITE, an in-memory DLL-search-order loader that retrieves decryption keys from a remote server and loads encrypted payloads (including CARBANAK), and RDFSNIFFER, a payload that hooks Win32 APIs to tamper with or hijack NCR Aloha Command Center Client sessions (allowing file upload/download, execute, and deletion). The blog details technical behaviors, code-signing evasions (signed sample with anomalous timestamps), sample hashes/C2s, Yara hunting ideas, MITRE ATT&CK mappings, and recommended detection approaches.