Uptime Hamster: 21d 12h 58mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza FIN7

FIN7

1 incidentes 1 paises 1 sectores threat-actor RU Ultimo: 2026-05-25
Aliases: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest
Ver en IntelTracker → APTTrail →
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.

Aliases del actor

GOLD NIAGARAITG14Carbon SpiderELBRUSSangria Tempest

Actores similares

Scattered Spiderthreat-actor · 2doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1dextorous-spideractor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Webunknownattack.mitre.orgOSINT
Motivacion