CDS2018-Technical-S5-ATT&CKing FIN7_The Value of Using Frameworks for Threat Intelligence-FINAL_clean
ID: 8b75db92-c012-484c-8522-a5153b6bb4fe
STIX ID: report--8b75db92-c012-484c-8522-a5153b6bb4fe
Threat Score
75/100
Uploaded: 2026-08-14
Published Date: 2018-10-12
Last Modified Date: 2018-10-12
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This presentation analyzes FIN7 — a financially motivated cybercriminal group active since 2015 — mapping their spearphishing-driven campaigns and multiple malware families (e.g., HALFBAKED, BELLHOP, POWERSOURCE, PILLOWMINT) to the MITRE ATT&CK framework; it details delivery, persistence, lateral movement, POS data exfiltration techniques, observable artifacts (registry keys, filenames, services), and detection/mitigation recommendations for defenders.
