FIN7 (Carbon Spider / Sangria Tempest) adversary-emulation playbook — revenue-targeted spearphishing with phone follow-up, EDR-evasion tradecraft, AD compromise, and big-game-hunting ransomware. Use when emulating a high-end financially-motivated crew that graduated from POS theft to ransomware. Triggers on: 'emulate FIN7', 'Carbanak', 'Carbon Spider', 'Sangria Tempest', 'big game hunting', 'EDR evasion', 'AvNeutralizer'.
71
87%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Tier-2 financially-motivated crew that evolved from point-of-sale theft to big-game-hunting ransomware (REvil / DarkSide / Black Basta links). Signature traits: revenue-selected targets, convincing business-themed spearphishing reinforced by phone calls, and mature EDR-evasion tooling (AvNeutralizer / AuKill). Authorized red-team emulation only.
../../references/apt-groups.md).plan/threat-profile.json){
"engagement_name": "<fill>",
"actor_name": "FIN7-like (Carbon Spider / Sangria Tempest)",
"actor_aliases": ["Carbon Spider", "Sangria Tempest", "GOLD NIAGARA", "ELBRUS", "ITG14"],
"group_id": "G0046",
"tier": "tier-2",
"sophistication": "high",
"motivation": "financial",
"initial_access": ["T1566.001", "T1566.002", "T1204.002"],
"key_ttps": ["T1059.001", "T1547.001", "T1053.005", "T1562.001", "T1003.001", "T1558.003", "T1021.001", "T1486", "T1567.002"],
"tools": ["Phishing kit + phone follow-up", "Sliver", "NetExec", "Impacket", "EDR-test/BYOVD (authorized)", "canary encryptor"],
"infrastructure": ["Business-themed lure domains", "Sliver HTTPS C2", "Engagement-owned exfil bucket"],
"recent_cti_delta": "Since 2020 shifted to big-game-hunting ransomware (REvil/DarkSide; Black Basta TTP overlap); AvNeutralizer/AuKill EDR-killer; targets shortlisted by revenue via Crunchbase/D&B/ZoomInfo, ransom sized to revenue.",
"confidence": "probable"
}| # | Phase | MITRE | Emulated action | Executing agent → skill |
|---|---|---|---|---|
| 1 | Recon | T1591 | Revenue-based target + staff shortlist (Crunchbase/D&B/ZoomInfo) | recon → /skills/standard/recon/osint/SKILL.md, /skills/standard/osint/SKILL.md |
| 2 | Initial Access | T1566.001 | Business-themed spearphish attachment + phone follow-up | phisher → /skills/standard/phisher/SKILL.md |
| 3 | Execution / C2 | T1204.002 / T1059.001 | Macro → loader → Sliver beacon | post-exploit → /skills/standard/post-exploit/c2-sliver/SKILL.md |
| 4 | Persistence | T1547.001 / T1053.005 | Run key + scheduled task | post-exploit → /skills/standard/post-exploit/privilege-escalation/SKILL.md |
| 5 | Defense Evasion | T1562.001 | EDR tamper / BYOVD (AvNeutralizer pattern, authorized) | post-exploit → /skills/standard/post-exploit/privilege-escalation/SKILL.md (shared defense-evasion auto-loaded) |
| 6 | Credential Access | T1003.001 | LSASS dump | post-exploit → /skills/standard/post-exploit/credential-access/SKILL.md |
| 7 | Discovery / AD | T1558.003 | BloodHound the domain; Kerberoast | ad → /skills/standard/ad/bloodhound-query/SKILL.md, /skills/standard/ad/kerberoasting/SKILL.md |
| 8 | Lateral | T1021.001 / T1570 | RDP/SMB + lateral tool transfer | post-exploit → /skills/standard/post-exploit/lateral-movement/SKILL.md; /skills/standard/ad/netexec/SKILL.md |
| 9 | Priv Esc to DA | T1003.006 | DCSync to domain dominance | ad → /skills/standard/ad/dcsync/SKILL.md |
| 10 | Exfiltration | T1567.002 | Stage + exfil to engagement bucket | post-exploit → /skills/standard/post-exploit/reporting/SKILL.md |
| 11 | Impact (CANARY) | T1486 | Demonstrate ransomware capability on canary only | post-exploit → /skills/standard/post-exploit/reporting/SKILL.md |
conops.json)recon — revenue-based target + staff selection (1).initial-access — spearphish attachment + phone follow-up (2).post-exploit — loader exec, EDR tamper, LSASS, AD recon/Kerberoast, lateral, DA via DCSync (3-9).c2 — Sliver (within 3).exfiltration — data theft + canary ransomware impact (10-11)./skills/standard/phisher/lure-deconfliction/SKILL.md); name in-scope staff.EMERGENCY abort: "production endpoint protection
disabled outside the authorized test host, or production data encrypted/exfiltrated."deconfliction.json + cleanup.json.0cf691e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.