{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "fin7",
    "slug": "fin7",
    "name": "FIN7",
    "shortName": "FIN7",
    "country": "Multiple / Non-state",
    "countryCode": "XX",
    "sponsorship": "criminal",
    "status": "active",
    "activeSince": "2013",
    "prominence": 82,
    "mitreGroupId": "G0046",
    "malpediaSlug": "fin7",
    "tagline": "Ran a fake security company that hired real penetration testers who did not know they were committing crimes. Stole over $1 billion.",
    "bio": "FIN7 is the most organisationally sophisticated criminal operation in the public record, and its defining detail is the front company.\n\nCombi Security presented itself as a legitimate penetration testing firm, with a website, offices, and a hiring pipeline. It recruited real security professionals through normal job channels, gave them normal-looking assignments, and paid them salaries. Many of those employees, according to U.S. federal charging documents, did not know they were conducting criminal intrusions — they believed they were performing authorised penetration tests for clients. The structure gave FIN7 a trained workforce, plausible deniability, and staff who could be replaced without compromising the operation.\n\nIts original business was point-of-sale malware against restaurant, hospitality, and gaming chains — Chipotle, Arby's, Red Robin, Saks Fifth Avenue, and Jason's Deli among many others. The Department of Justice has assessed losses exceeding $1 billion, with more than 20 million payment card records stolen from over 6,500 point-of-sale terminals.\n\nDelivery combined phishing with genuine tradecraft: operators would call the target restaurant by phone to ensure the malicious attachment had been opened and offer help if it had not.\n\nThe group has adapted repeatedly under pressure. After arrests of senior members in 2018 and the 2021 sentencing of a manager, it moved into ransomware — associated with the Darkside, BlackMatter, and ALPHV operations — and into more creative supply-side schemes, including mailing malicious USB drives to targets in packaging impersonating Best Buy and Amazon, complete with gift cards.",
    "attribution": {
      "sponsor": "None — financially motivated criminal group",
      "service": "Assessed Eastern European leadership, operating through the Combi Security front company",
      "confidence": "confirmed",
      "summary": "Multiple members have been arrested, extradited, and sentenced. Three Ukrainian nationals holding senior positions were charged in 2018; Fedir Hladyr, a systems administrator, was sentenced to ten years in 2021, and Andrii Kolpakov to seven years. Charging documents establish Combi Security as a front company that recruited security professionals who were, in many cases, unaware their work was criminal.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "Three Members of Notorious International Cybercrime Group FIN7 in Custody",
          "url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacking-over-100",
          "date": "2018-08-01"
        },
        {
          "org": "U.S. Department of Justice",
          "title": "High-Level Manager of FIN7 Sentenced to Ten Years in Prison",
          "url": "https://www.justice.gov/opa/pr/high-level-organizer-notorious-hacking-group-fin7-sentenced-ten-years-prison",
          "date": "2021-04-16"
        }
      ]
    },
    "motivations": [
      "financial-gain"
    ],
    "targetSectors": [
      "Retail & Hospitality",
      "Financial Services",
      "Healthcare",
      "Technology",
      "Manufacturing",
      "Transportation",
      "Education",
      "Legal",
      "Energy"
    ],
    "targetCountries": [
      "United States",
      "United Kingdom",
      "France",
      "Australia",
      "Canada",
      "Germany"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "FIN7",
        "url": "https://attack.mitre.org/groups/G0046/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Sangria Tempest",
        "correlation": "exact",
        "note": "Formerly ELBRUS"
      },
      {
        "org": "crowdstrike",
        "name": "Carbon Spider",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "FIN7",
        "correlation": "exact"
      },
      {
        "org": "secureworks",
        "name": "GOLD NIAGARA",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Carbon Spider",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "FIN7",
        "correlation": "exact"
      },
      {
        "org": "symantec",
        "name": "Carbanak",
        "correlation": "partial",
        "note": "Carbanak names a related but distinct group and its malware; frequently conflated with FIN7"
      },
      {
        "org": "kaspersky",
        "name": "Carbanak",
        "correlation": "partial",
        "note": "Kaspersky's original Carbanak research covers overlapping but not identical activity"
      },
      {
        "org": "redcanary",
        "name": "FIN7",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "CARBANAK",
        "type": "backdoor",
        "custom": true,
        "description": "Full-featured backdoor with screen recording, keylogging, and remote control, used for extended reconnaissance of financial workflows.",
        "malpediaSlug": "win.carbanak"
      },
      {
        "name": "GRIFFON / BOOSTWRITE",
        "type": "loader",
        "custom": true,
        "description": "JavaScript implant and loader chain used for staged payload delivery and host profiling."
      },
      {
        "name": "BadUSB packages",
        "type": "utility",
        "custom": true,
        "description": "Malicious USB drives mailed to targets in packaging impersonating Best Buy and Amazon, with gift cards included for credibility."
      },
      {
        "name": "Point-of-sale malware",
        "type": "malware",
        "custom": true,
        "description": "Memory-scraping implants harvesting payment card track data from POS terminals."
      },
      {
        "name": "AuKill / EDR killers",
        "type": "utility",
        "custom": true,
        "description": "Tools using vulnerable signed drivers to terminate endpoint detection products from kernel space."
      },
      {
        "name": "Ransomware affiliations",
        "type": "ransomware",
        "custom": false,
        "description": "Associated with Darkside, BlackMatter, and ALPHV operations after the group's pivot from card theft."
      }
    ],
    "techniques": [
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access",
        "note": "Followed by a phone call to the target to confirm the attachment was opened"
      },
      {
        "tCode": "T1598.004",
        "name": "Phishing for Information: Spearphishing Voice",
        "tactic": "Reconnaissance"
      },
      {
        "tCode": "T1091",
        "name": "Replication Through Removable Media",
        "tactic": "Initial Access",
        "note": "BadUSB drives mailed in impersonated retailer packaging"
      },
      {
        "tCode": "T1059.007",
        "name": "Command and Scripting Interpreter: JavaScript",
        "tactic": "Execution"
      },
      {
        "tCode": "T1005",
        "name": "Data from Local System",
        "tactic": "Collection",
        "note": "Payment card track data scraped from POS terminal memory"
      },
      {
        "tCode": "T1113",
        "name": "Screen Capture",
        "tactic": "Collection",
        "note": "Video recording of operator sessions to learn financial workflows"
      },
      {
        "tCode": "T1562.001",
        "name": "Impair Defenses: Disable or Modify Tools",
        "tactic": "Defense Evasion",
        "note": "Vulnerable signed drivers used to terminate EDR"
      },
      {
        "tCode": "T1486",
        "name": "Data Encrypted for Impact",
        "tactic": "Impact",
        "note": "Ransomware deployment after the pivot from card theft"
      },
      {
        "tCode": "T1657",
        "name": "Financial Theft",
        "tactic": "Impact",
        "note": "Over $1bn assessed in losses across the operation's lifetime"
      },
      {
        "tCode": "T1585.001",
        "name": "Establish Accounts: Social Media Accounts",
        "tactic": "Resource Development",
        "note": "Combi Security front company with a genuine hiring pipeline"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2017-0199",
        "firstExploited": "2017-04-01",
        "usage": "OLE2link RTF exploit used in phishing against hospitality and restaurant targets.",
        "source": {
          "org": "Mandiant / FireEye",
          "title": "FIN7 Evolution and the Phishing LNK",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/fin7-phishing-lnk",
          "date": "2017-04-24"
        }
      },
      {
        "cveId": "CVE-2016-0167",
        "firstExploited": "2016-04-01",
        "zeroDay": true,
        "usage": "Win32k privilege escalation exploited as a zero-day in targeted intrusions against financial and retail organisations.",
        "source": {
          "org": "Mandiant / FireEye",
          "title": "Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/threat-actor-leverages-windows-zero-day-exploit-in-payment-card-data-attacks",
          "date": "2016-05-10"
        }
      },
      {
        "cveId": "CVE-2021-31207",
        "firstExploited": "2021-09-01",
        "usage": "ProxyShell component exploited for Exchange access preceding ransomware deployment.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "FIN7 targeting and ransomware affiliation",
          "url": "https://www.microsoft.com/en-us/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/",
          "date": "2022-05-09"
        }
      },
      {
        "cveId": "CVE-2020-1472",
        "firstExploited": "2021-01-01",
        "usage": "Zerologon used for rapid domain escalation during ransomware-precursor intrusions.",
        "source": {
          "org": "Mandiant",
          "title": "FIN7 intrusion analysis and ransomware transition",
          "url": "https://cloud.google.com/blog/topics/threat-intelligence/fin7-shifted-operations-ransomware",
          "date": "2022-04-04"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "lockbit",
        "type": "supplier",
        "confidence": "moderate",
        "note": "FIN7 has been assessed as supplying access and tooling into the ransomware affiliate ecosystem."
      },
      {
        "relatedActorId": "cl0p",
        "type": "operational-overlap",
        "confidence": "low",
        "note": "Both long-lived criminal operations that evolved through several monetisation models."
      },
      {
        "relatedActorId": "scattered-spider",
        "type": "operational-overlap",
        "confidence": "low",
        "note": "Both use social engineering as a primary vector, with entirely different demographics and organisational structures."
      }
    ],
    "reports": [
      {
        "org": "Mandiant / FireEye",
        "title": "Behind the CARBANAK Backdoor",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/behind-the-carbanak-backdoor",
        "date": "2019-04-22"
      },
      {
        "org": "U.S. Department of Justice",
        "title": "Three Members of International Cybercrime Group FIN7 in Custody",
        "url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacking-over-100",
        "date": "2018-08-01"
      },
      {
        "org": "Mandiant",
        "title": "FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/evolution-of-fin7",
        "date": "2022-04-04"
      }
    ],
    "campaigns": [
      {
        "id": "fin7-pos",
        "actorId": "fin7",
        "name": "Point-of-Sale Card Theft Campaign",
        "date": "2015-01-01",
        "endDate": "2018-08-01",
        "significance": "landmark",
        "targetSectors": [
          "Retail & Hospitality",
          "Financial Services"
        ],
        "targetCountries": [
          "United States",
          "United Kingdom",
          "France",
          "Australia"
        ],
        "cveIds": [
          "CVE-2017-0199",
          "CVE-2016-0167"
        ],
        "summary": "Theft of over 20 million payment card records from more than 6,500 point-of-sale terminals across restaurant, hospitality, and gaming chains, with assessed losses exceeding $1 billion. Operated through Combi Security, a front company that recruited security professionals who largely did not know their work was criminal.",
        "sources": [
          {
            "org": "U.S. Department of Justice",
            "title": "Three Members of International Cybercrime Group FIN7 in Custody",
            "url": "https://www.justice.gov/opa/pr/three-members-notorious-international-cybercrime-group-fin7-custody-role-attacking-over-100",
            "date": "2018-08-01"
          }
        ]
      }
    ],
    "flag": "🏴",
    "profile": "/apt/fin7/"
  }
}