Key Facts
- Attributed Country: Transnational / Eastern Europe.
- ATT&CK Group Reference: G0046 (FIN7).
- Linked to 1 primary court prosecution records.
- Identified 3 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1566.001 Spearphishing Attachment | 1 incidents |
| T1059.001 PowerShell | 1 incidents |
| T1041 Exfiltration Over C2 Channel | 1 incidents |
| T1056.001 Keylogging | 1 incidents |
| T1113 Screen Capture | 1 incidents |
| T1074.001 Local Data Staging | 1 incidents |
| T1020 Automated Exfiltration | 1 incidents |
Prosecution Cases Attributed to This Actor
U.S. v. Hladyr, Kolpakov & Iarmak (FIN7 Cybercrime Syndicate)
Prosecution of senior leaders of the FIN7 transnational cybercrime syndicate who hacked into thousands of computer systems across the United States, stealing more than 20 million customer credit card records from restaurants and hospitality chains.
Targeted Defensive Hardening for FIN7
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.