logo

FIN7__2019__FIN7.5_the_infamous_cybercrime_rig_FIN7_continues_its_activities.pdf

ID: 756eacb7-9baa-48a9-b75a-11ab12681f8c

STIX ID: report--756eacb7-9baa-48a9-b75a-11ab12681f8c

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2019-05-09

Last Modified Date: 2019-05-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab describes continued FIN7 activity despite 2018 arrests, detailing sophisticated spearphishing campaigns that deliver malicious Office documents and a modular JScript implant called GRIFFON which loads reconnaissance, Meterpreter (TinyMet) downloader, screenshot and persistence modules. The report links FIN7 to related clusters (AveMaria infostealer, CobaltGoblin/EmpireMonkey, and a CopyPaste actor), provides extensive IOCs and infrastructure analysis (C2 domains, IPs, typosquatting and decoy 302 redirects), and highlights the group's focus on financial theft and supplier/service targets.