Reconnaissance
1 technique·derived
Spearphishing Voice.
Ran a fake security company that hired real penetration testers who did not know they were committing crimes. Stole over $1 billion.
FIN7 is the most organisationally sophisticated criminal operation in the public record, and its defining detail is the front company.
Combi Security presented itself as a legitimate penetration testing firm, with a website, offices, and a hiring pipeline. It recruited real security professionals through normal job channels, gave them normal-looking assignments, and paid them salaries. Many of those employees, according to U.S. federal charging documents, did not know they were conducting criminal intrusions — they believed they were performing authorised penetration tests for clients. The structure gave FIN7 a trained workforce, plausible deniability, and staff who could be replaced without compromising the operation.
Its original business was point-of-sale malware against restaurant, hospitality, and gaming chains — Chipotle, Arby's, Red Robin, Saks Fifth Avenue, and Jason's Deli among many others. The Department of Justice has assessed losses exceeding $1 billion, with more than 20 million payment card records stolen from over 6,500 point-of-sale terminals.
Delivery combined phishing with genuine tradecraft: operators would call the target restaurant by phone to ensure the malicious attachment had been opened and offer help if it had not.
The group has adapted repeatedly under pressure. After arrests of senior members in 2018 and the 2021 sentencing of a manager, it moved into ransomware — associated with the Darkside, BlackMatter, and ALPHV operations — and into more creative supply-side schemes, including mailing malicious USB drives to targets in packaging impersonating Best Buy and Amazon, complete with gift cards.
Down to the named unit where public evidence supports it.
Multiple members have been arrested, extradited, and sentenced. Three Ukrainian nationals holding senior positions were charged in 2018; Fedir Hladyr, a systems administrator, was sentenced to ten years in 2021, and Andrii Kolpakov to seven years. Charging documents establish Combi Security as a front company that recruited security professionals who were, in many cases, unaware their work was criminal.
Attributing sources
10 designators across 10 organisations.
2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Names activity clusters descriptively rather than by a fixed nation-state taxonomy, and generally adopts the prevailing community name for established state actors. Coverage skews toward commodity and eCrime threats seen in managed-detection telemetry.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
Insect, animal, and plant names assigned in the order clusters were first identified.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Full-featured backdoor with screen recording, keylogging, and remote control, used for extended reconnaissance of financial workflows.
Malpedia ↗JavaScript implant and loader chain used for staged payload delivery and host profiling.
Malicious USB drives mailed to targets in packaging impersonating Best Buy and Amazon, with gift cards included for credibility.
Memory-scraping implants harvesting payment card track data from POS terminals.
Tools using vulnerable signed drivers to terminate endpoint detection products from kernel space.
Shared, commodity & living-off-the-land
Associated with Darkside, BlackMatter, and ALPHV operations after the group's pivot from card theft.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by FIN7 | ||
|---|---|---|---|---|
| CVE-2021-31207 | — | — | 1 Sep 2021 | ProxyShell component exploited for Exchange access preceding ransomware deployment.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2020-1472KEVransomware | 10.0 | Windows NetlogonMicrosoft | 1 Jan 2021 | Zerologon used for rapid domain escalation during ransomware-precursor intrusions.SRCMandiant ↗ |
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Apr 2017 | OLE2link RTF exploit used in phishing against hospitality and restaurant targets.SRCMandiant / FireEye ↗ |
| CVE-2016-01670-dayKEVransomware | 7.8 | Windows Win32kMicrosoft | 1 Apr 2016 | Win32k privilege escalation exploited as a zero-day in targeted intrusions against financial and retail organisations.SRCMandiant / FireEye ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Spearphishing Voice.
1 technique·derived
Combi Security front company with a genuine hiring pipeline.
2 techniques·derived
Followed by a phone call to the target to confirm the attachment was opened. BadUSB drives mailed in impersonated retailer packaging.
1 technique·derived
JavaScript.
1 technique·derived
Vulnerable signed drivers used to terminate EDR.
2 techniques·derived
Payment card track data scraped from POS terminal memory. Video recording of operator sessions to learn financial workflows.
2 techniques·derived
Ransomware deployment after the pivot from card theft. Over $1bn assessed in losses across the operation's lifetime.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Combi Security front company with a genuine hiring pipeline
Followed by a phone call to the target to confirm the attachment was opened
BadUSB drives mailed in impersonated retailer packaging
Vulnerable signed drivers used to terminate EDR
Payment card track data scraped from POS terminal memory
Video recording of operator sessions to learn financial workflows
Ransomware deployment after the pivot from card theft
Over $1bn assessed in losses across the operation's lifetime
Theft of over 20 million payment card records from more than 6,500 point-of-sale terminals across restaurant, hospitality, and gaming chains, with assessed losses exceeding $1 billion. Operated through Combi Security, a front company that recruited security professionals who largely did not know their work was criminal.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
FIN7 has been assessed as supplying access and tooling into the ransomware affiliate ecosystem.
Both long-lived criminal operations that evolved through several monetisation models.
Both use social engineering as a primary vector, with entirely different demographics and organisational structures.
Curated links to the reports that established what is known about this group.