logo

FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings

ID: e52b4be9-8e26-44a1-9dda-85cf8d7e0687

STIX ID: report--e52b4be9-8e26-44a1-9dda-85cf8d7e0687

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2017-05-17

Last Modified Date: 2017-05-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye observed a FIN7 spear-phishing campaign targeting personnel involved in SEC filings using spoofed EDGAR emails and malicious Word attachments that dropped VBS/PowerShell backdoors (POWERSOURCE and TEXTMATE) leveraging DNS TXT for command-and-control; operators also delivered Cobalt Strike stagers and CARBANAK samples. The campaign targeted 11 U.S.-based organizations across multiple sectors, presented fileless and registry/ADS persistence techniques that complicate detection, and prompted a coordinated FireEye Community Protection Event to deploy detections and contain the activity.