FIN7__2021__Anomali_FIN7-Windows11-Themed-Drop-Javascript-Backdoor_09-02-2021.pdf
ID: 7e431232-c024-435d-bb39-3161b0d268bc
STIX ID: report--7e431232-c024-435d-bb39-3161b0d268bc
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2021-09-04
Last Modified Date: 2021-09-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Anomali Threat Research details a FIN7 campaign using Windows 11 Alpha–themed Word documents with VBA macros to drop an obfuscated JavaScript backdoor; the analysis includes deobfuscation steps, anti-analysis checks (language, VM, memory, domain), IOCs (file hashes, domains, IP 85.14.253.178), MITRE ATT&CK mappings, and attribution rationale focusing on POS-targeting (Clearmind) and historical FIN7 TTPs.
