FIN7__2019__FIN7.5_the_infamous_cybercrime_rig_FIN7_continues_its_activities.pdf
ID: 756eacb7-9baa-48a9-b75a-11ab12681f8c
STIX ID: report--756eacb7-9baa-48a9-b75a-11ab12681f8c
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2019-05-09
Last Modified Date: 2019-05-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kaspersky Lab describes continued FIN7 activity despite 2018 arrests, detailing sophisticated spearphishing campaigns that deliver malicious Office documents and a modular JScript implant called GRIFFON which loads reconnaissance, Meterpreter (TinyMet) downloader, screenshot and persistence modules. The report links FIN7 to related clusters (AveMaria infostealer, CobaltGoblin/EmpireMonkey, and a CopyPaste actor), provides extensive IOCs and infrastructure analysis (C2 domains, IPs, typosquatting and decoy 302 redirects), and highlights the group's focus on financial theft and supplier/service targets.
