logo

FIN7__2021__Anomali_FIN7-Windows11-Themed-Drop-Javascript-Backdoor_09-02-2021.pdf

ID: 7e431232-c024-435d-bb39-3161b0d268bc

STIX ID: report--7e431232-c024-435d-bb39-3161b0d268bc

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2021-09-04

Last Modified Date: 2021-09-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Anomali Threat Research details a FIN7 campaign using Windows 11 Alpha–themed Word documents with VBA macros to drop an obfuscated JavaScript backdoor; the analysis includes deobfuscation steps, anti-analysis checks (language, VM, memory, domain), IOCs (file hashes, domains, IP 85.14.253.178), MITRE ATT&CK mappings, and attribution rationale focusing on POS-targeting (Clearmind) and historical FIN7 TTPs.