FIN7

Description

FIN7 is a financially-motivated threat group that has primarily targeted the U.S. retail, restaurant, and hospitality sectors since mid-2015. They often use point-of-sale malware. A portion of FIN7 was run out of a front company called Combi Security. FIN7 is sometimes referred to as Carbanak, Anunak, but these appear to be two groups using the same Carbanak malware and are therefore tracked separately.

The reports about arrests made of the mastermind of Carbanak instead of FIN7. However, security research teams keep referring to this arrest for all FIN7 activities since.

Names

NameName-Giver
FIN7FireEye
Gold NiagaraSecureWorks
CalciumSymantec
NavigatorFox-IT
ATK 32Thales
APT-C-11Qihoo 360
ITG14IBM
TAG-CR1Recorded Future
GrayAlphaRecorded Future

Country

Motivation

  • Financial crime

First Seen

2013

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

c3f1f1ff-7d79-4385-bb5b-340c252c5a77

Last Card Change

2025-06-28