logo

CDS2018-Technical-S5-ATT&CKing FIN7_The Value of Using Frameworks for Threat Intelligence-FINAL_clean

ID: 8b75db92-c012-484c-8522-a5153b6bb4fe

STIX ID: report--8b75db92-c012-484c-8522-a5153b6bb4fe

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2018-10-12

Last Modified Date: 2018-10-12

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This presentation analyzes FIN7 — a financially motivated cybercriminal group active since 2015 — mapping their spearphishing-driven campaigns and multiple malware families (e.g., HALFBAKED, BELLHOP, POWERSOURCE, PILLOWMINT) to the MITRE ATT&CK framework; it details delivery, persistence, lateral movement, POS data exfiltration techniques, observable artifacts (registry keys, filenames, services), and detection/mitigation recommendations for defenders.