Skip to content
Multiple / Non-stateCriminalActiveMITRE G0046Malpedia ↗

FIN7

Ran a fake security company that hired real penetration testers who did not know they were committing crimes. Stole over $1 billion.

Open MITRE Navigator layer ↗Download profile JSON
Active
2013–present
Motivation
Financial Gain
Aliases
10
Exploited CVEs
4
ATT&CK techniques
10
Cited sources
9

Overview

FIN7 is the most organisationally sophisticated criminal operation in the public record, and its defining detail is the front company.

Combi Security presented itself as a legitimate penetration testing firm, with a website, offices, and a hiring pipeline. It recruited real security professionals through normal job channels, gave them normal-looking assignments, and paid them salaries. Many of those employees, according to U.S. federal charging documents, did not know they were conducting criminal intrusions — they believed they were performing authorised penetration tests for clients. The structure gave FIN7 a trained workforce, plausible deniability, and staff who could be replaced without compromising the operation.

Its original business was point-of-sale malware against restaurant, hospitality, and gaming chains — Chipotle, Arby's, Red Robin, Saks Fifth Avenue, and Jason's Deli among many others. The Department of Justice has assessed losses exceeding $1 billion, with more than 20 million payment card records stolen from over 6,500 point-of-sale terminals.

Delivery combined phishing with genuine tradecraft: operators would call the target restaurant by phone to ensure the malicious attachment had been opened and offer help if it had not.

The group has adapted repeatedly under pressure. After arrests of senior members in 2018 and the 2021 sentencing of a manager, it moved into ransomware — associated with the Darkside, BlackMatter, and ALPHV operations — and into more creative supply-side schemes, including mailing malicious USB drives to targets in packaging impersonating Best Buy and Amazon, complete with gift cards.

Attribution

Down to the named unit where public evidence supports it.

None — financially motivated criminal groupAssessed Eastern European leadership, operating through the Combi Security front companyConfirmed

Multiple members have been arrested, extradited, and sentenced. Three Ukrainian nationals holding senior positions were charged in 2018; Fedir Hladyr, a systems administrator, was sentenced to ten years in 2021, and Andrii Kolpakov to seven years. Charging documents establish Combi Security as a front company that recruited security professionals who were, in many cases, unaware their work was criminal.

Attributing sources

Cross-vendor naming crosswalk

10 designators across 10 organisations.

2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

MITRE ATT&CK

index ↗
  • FIN7

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Sangria TempestFormerly ELBRUS

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Carbon Spider

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • FIN7

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • GOLD NIAGARA

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Carbon Spider

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Red Canary

index ↗
  • FIN7

Names activity clusters descriptively rather than by a fixed nation-state taxonomy, and generally adopts the prevailing community name for established state actors. Coverage skews toward commodity and eCrime threats seen in managed-detection telemetry.

Kaspersky GReAT

index ↗
  • CarbanakpartialKaspersky's original Carbanak research covers overlapping but not identical activity

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Symantec (Broadcom)

index ↗
  • CarbanakpartialCarbanak names a related but distinct group and its malware; frequently conflated with FIN7

Insect, animal, and plant names assigned in the order clusters were first identified.

CISA / NSA / FBI

index ↗
  • FIN7

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUnited KingdomFranceAustraliaCanadaGermany

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

CARBANAKbackdoor

Full-featured backdoor with screen recording, keylogging, and remote control, used for extended reconnaissance of financial workflows.

Malpedia ↗
GRIFFON / BOOSTWRITEloader

JavaScript implant and loader chain used for staged payload delivery and host profiling.

BadUSB packagesutility

Malicious USB drives mailed to targets in packaging impersonating Best Buy and Amazon, with gift cards included for credibility.

Point-of-sale malwaremalware

Memory-scraping implants harvesting payment card track data from POS terminals.

AuKill / EDR killersutility

Tools using vulnerable signed drivers to terminate endpoint detection products from kernel space.

Shared, commodity & living-off-the-land

Ransomware affiliationsransomware

Associated with Darkside, BlackMatter, and ALPHV operations after the group's pivot from card theft.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by FIN7
CVE-2021-312071 Sep 2021ProxyShell component exploited for Exchange access preceding ransomware deployment.SRCMicrosoft Threat Intelligence
CVE-2020-1472KEVransomware10.01 Jan 2021Zerologon used for rapid domain escalation during ransomware-precursor intrusions.SRCMandiant
CVE-2017-0199KEVransomware7.81 Apr 2017OLE2link RTF exploit used in phishing against hospitality and restaurant targets.SRCMandiant / FireEye
CVE-2016-01670-dayKEVransomware7.81 Apr 2016Win32k privilege escalation exploited as a zero-day in targeted intrusions against financial and retail organisations.SRCMandiant / FireEye

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 7 tactics · 8 with actor-specific notes

Resource Development

1

Initial Access

2

Defense Evasion

1

Collection

2

Impact

2

Campaign timeline

  1. landmark

    Point-of-Sale Card Theft Campaign

    Theft of over 20 million payment card records from more than 6,500 point-of-sale terminals across restaurant, hospitality, and gaming chains, with assessed losses exceeding $1 billion. Operated through Combi Security, a front company that recruited security professionals who largely did not know their work was criminal.

    CVE-2017-0199CVE-2016-0167Retail & HospitalityFinancial Services

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.