CtrlK
BlogDocsLog inGet started
Tessl Logo

fin7-carbanak

Adversary-emulation profile for FIN7 (G0046; aka Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS) — a financially motivated Russian-speaking crime group, mapping its TTPs to Decepticon tooling for authorized red-team emulation.

49

Quality

53%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/fin7-carbanak/SKILL.md
SKILL.md
Quality
Evals
Security

FIN7 (Carbanak, Carbon Spider, Sangria Tempest) — Adversary Emulation Profile

FIN7 (MITRE ATT&CK G0046; also tracked as Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS, and ITG14) is one of the most prolific and best-documented financially motivated cybercrime groups, active since at least 2013. Originally infamous for large-scale point-of-sale (POS) intrusions to steal payment-card data — operating behind the front company "Combi Security" — the group pivoted to "big game hunting" ransomware around 2020, running its own Darkside/BlackMatter Ransomware-as-a-Service and acting as an affiliate/tooling supplier for REvil, Cl0p, Black Basta, ALPHV/BlackCat, LockBit, and others. FIN7 is characterized by disciplined operational tradecraft: convincing social engineering (including spearphishing of IT staff and physically mailed BadUSB drives), heavily obfuscated custom loaders (POWERTRASH), signature backdoors (Carbanak/Anunak, Lizar/Diceloader), purchased/cracked commercial tooling (Cobalt Strike, Core Impact), and a productized EDR-killer (AvNeutralizer/AuKill) sold on criminal forums.

Attribution & motivation

  • Sponsor / nation: Not a state-sponsored actor. FIN7 is an organized criminal enterprise assessed by multiple vendors to be Russian-speaking / Russia-based, with confirmed Ukrainian national members (per the 2018 U.S. DOJ indictment).
  • Motivation: Financial. Early operations monetized stolen payment-card data sold on carding/darknet markets; later operations monetize via ransomware extortion (own RaaS brands and as a ransomware affiliate) and by selling intrusion tooling (e.g., the AvNeutralizer EDR killer) to other crews.
  • Confidence: High for the activity cluster and financial motivation (corroborated by DOJ indictments/convictions and consistent CrowdStrike, Mandiant, Microsoft, SentinelOne, and Secureworks reporting). Note that the "Carbanak" backdoor has been used by more than one actor, so backdoor-only attributions to FIN7 should be treated with lower confidence than TTP-clustered attributions.

Targeting

  • Sectors: Historically heavy on retail, restaurant, hospitality, and gaming (POS-era payment-card theft). Post-2020 ransomware era broadened to software, consulting, financial services, medical equipment/pharmaceutical, cloud services, media, food & beverage, transportation, utilities, manufacturing, legal, and the public sector, plus the automotive industry.
  • Regions: Predominantly the United States (the DOJ described theft of card data from 100+ U.S. companies across 47 states), with European victims also reported.
  • Victim profile: During POS operations, customer-facing businesses processing large card volumes. In the ransomware/BGH era, victim selection is revenue-driven (targets filtered by company revenue using ZoomInfo) and FIN7 specifically phishes IT staff with elevated administrative privileges to accelerate domain compromise.

Notable campaigns

  • 2017 — Restaurant/retail POS theft (Chipotle and others): Large-scale spearphishing of hospitality/restaurant chains delivering Carbanak/HALFBAKED and POS scrapers (e.g., Pillowmint) to harvest payment-card data. (CrowdStrike, Secureworks GOLD NIAGARA)
  • 2018 — Saks Fifth Avenue / Lord & Taylor breach: POS compromise of high-end retailers exposing roughly 5 million payment cards sold on darknet markets. (Multiple vendor reporting)
  • Aug 1, 2018 — DOJ indictment & arrests: Three Ukrainian nationals (Fedir Hladyr, Dmytro Fedorov, Andrii Kolpakov) charged; the indictment exposed the Combi Security front company used to recruit operators. (CrowdStrike "Arrests Put New Focus on CARBON SPIDER")
  • 2020 — Pivot to big game hunting: FIN7 stands up its own RaaS (Darkside, later BlackMatter) and begins deploying ransomware as the end objective. (CrowdStrike "CARBON SPIDER Embraces Big Game Hunting")
  • Apr 2021 — Member sentencing: Fedir Hladyr sentenced to 10 years following a 2019 guilty plea. (CrowdStrike / DOJ)
  • Oct 2021 — "Bastion Secure" fake-pentest-firm scheme: FIN7 ran a sham security company to hire legitimate penetration testers/IT specialists who unknowingly performed ransomware-intrusion work. (Vendor reporting)
  • 2022 — "Checkmarks" automated exploitation platform: FIN7 built an automated attack system mass-exploiting public-facing Microsoft Exchange via ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) with an Auto-SQLi (SQLMap) module; intrusions hit U.S. manufacturing, legal, and public-sector firms (medium-confidence attribution). (SentinelOne "FIN7 Reboot")
  • 2022 onward — AvNeutralizer / AuKill EDR-killer: FIN7 developed an EDR-tampering tool (first operational use ~mid-2022; an updated version abuses the Windows ProcLaunchMon.sys/Process Explorer driver) and sold it on criminal forums; used by Black Basta and later multiple ransomware crews. (SentinelOne, IBM)
  • Apr 2023 — Return with Cl0p ransomware (Sangria Tempest): Microsoft observed FIN7 use POWERTRASH to load the Lizar post-exploitation tool, then OpenSSH and Impacket for lateral movement before deploying Cl0p ransomware. (Microsoft / The Hacker News)
  • Late 2023 (reported Apr 2024) — Automaker IT-staff spearphishing: FIN7 phished privileged IT employees at a large U.S.-based multinational automaker using a typosquatted Advanced IP Scanner site (advanced-ip-sccanner[.]commyipscanner[.]com), a Dropbox-hosted WsTaskLoad.exe, POWERTRASH, the Anunak/Carbanak backdoor, and OpenSSH for persistence. (BlackBerry / BleepingComputer)

TTPs by ATT&CK tactic

Initial Access

  • T1566.001 — Spearphishing Attachment: Weaponized Microsoft Office documents and RTF files (often DDE-triggered) sent to targeted employees.
  • T1566.002 — Spearphishing Link: Phishing emails with malicious / typosquatted links (e.g., fake Advanced IP Scanner download site) redirecting to attacker-controlled hosting (Dropbox).
  • T1091 — Replication Through Removable Media: Physically mails BadUSB drives that emulate a keyboard to victims to trigger malware downloads.
  • T1190 — Exploit Public-Facing Application: Mass-exploited Microsoft Exchange (ProxyShell, incl. CVE-2021-31207) via the automated "Checkmarks" platform with an Auto-SQLi module.
  • T1195.002 — Compromise Software Supply Chain: Trojanized legitimate digital products / software supply chains to gain access.
  • T1078.003 — Valid Accounts (Local Accounts): Reused compromised credentials to obtain SYSTEM-level access on Exchange servers.

Execution

  • T1204.001 / T1204.002 — User Execution (Malicious Link / Malicious File): Lures victims into clicking links or double-clicking attachments (image lures that execute hidden LNK files; JSS Loader/Harpy delivery).
  • T1059.001 — PowerShell: POWERTRASH heavily obfuscated PowerShell reflectively loads PE payloads in memory (Carbanak, Lizar/Diceloader, Core Impact).
  • T1059.003 / .005 / .007 — Windows Command Shell / VBScript / JavaScript: cmd.exe, VBS, and JS scripting for on-host tasking; T1059 SQL scripts for victim-machine tasks.
  • T1559.002 — Dynamic Data Exchange: Office documents abusing DDE for code execution.
  • T1218.005 / .011 — Mshta / Rundll32: mshta.exe runs VBScript; rundll32.exe executes malware DLLs.
  • T1047 — Windows Management Instrumentation: WMI used to install malware on targeted systems.
  • T1674 — Input Injection: Malicious USBs emulate keystrokes to launch PowerShell downloaders.
  • T1620 — Reflective Code Loading: Loads .NET assemblies via Reflection.Assembly::Load (and in-memory PE loading via POWERTRASH).

Persistence

  • T1547.001 — Registry Run Keys / Startup Folder: Run/RunOnce keys and Startup-folder items.
  • T1543.003 — Windows Service: Creates new Windows services tied to startup.
  • T1053.005 — Scheduled Task: Persistence tasks (e.g., masqueraded "AdobeFlashSync"); also uses OpenSSH for persistence.
  • T1546.011 — Application Shimming: Application shim databases for persistence.
  • T1569.002 — Service Execution: Starts the SSH service via sc start sshd.

Privilege Escalation

  • T1210 — Exploitation of Remote Services: Exploited ZeroLogon (CVE-2020-1472) against vulnerable domain controllers.
  • T1078.003 / T1543.003 / T1053.005 / T1547.001: Service- and task-based escalation/persistence as above.

Defense Evasion

  • T1027.010 / .016 — Command Obfuscation / Junk Code Insertion: Fragmented strings, env-var indirection, stdin, character-replacement, and random junk code.
  • T1140 — Deobfuscate/Decode Files or Information: certutil to decode PowerShell; XOR-deobfuscation routines.
  • T1553.002 — Code Signing: Carbanak payloads and phishing documents signed with purchased/abused certificates.
  • T1562.001 — Impair Defenses (Disable or Modify Tools): AvNeutralizer/AuKill tampers with/kills EDR and AV (kernel-mode abuse of ProcLaunchMon.sys / Process Explorer driver). (SentinelOne; mapped to T1562.001)
  • T1564.001 / .003 — Hidden Files & Directories / Hidden Window: attrib +h to hide an SSH folder; .txt-concealed PowerShell.
  • T1036.004 / .005 — Masquerading: Scheduled task named "AdobeFlashSync"; ransomware staged as sleep.exe; loader masquerades as WsTaskLoad.exe.
  • T1571 — Non-Standard Port: Port/protocol mismatches on 53/80/443/8080 and firewall openings on TCP 59999 and 9898.
  • T1497.002 — Virtualization/Sandbox Evasion (User Activity Based Checks): Payloads detonate only on user interaction (double-click of embedded image).

Credential Access

  • T1558.003 — Kerberoasting: PowerShell-driven Kerberoasting for credential access and lateral movement.
  • T1003 — OS Credential Dumping: Uses Mimikatz (S0002) to harvest credentials. (ATT&CK software mapping; mapped to T1003)

Discovery

  • T1087.002 — Domain Account Discovery: Enumerates domain admins via PowerShell and csvde.exe.
  • T1069.002 — Permission Groups (Domain Groups): net group to enumerate domain groups.
  • T1057 — Process Discovery: tasklist /v via WsTaskLoad.exe / PowerShell.
  • T1082 — System Information Discovery: csvde.exe and WsTaskLoad for host enumeration.
  • T1033 — System Owner/User Discovery: cmd.exe /C quser for active sessions.
  • T1124 — System Time Discovery: net time via PowerShell script.
  • T1591 / T1591.004 — Gather Victim Org Information / Identify Roles: ZoomInfo to filter targets by revenue and to identify IT staff with elevated admin rights (uses AdFind, S0552, internally).

Lateral Movement

  • T1021.001 — RDP: Remote Desktop for lateral movement.
  • T1021.004 — SSH: OpenSSH for lateral movement and reverse tunnels.
  • T1021.005 — VNC: TightVNC to control compromised hosts.
  • Impacket / CrackMapExec (S0488): Used for remote execution/spread in the ransomware era (CrackMapExec is an ATT&CK-listed FIN7 tool).

Collection

  • T1005 — Data from Local System: Collects files and sensitive data from compromised hosts.
  • T1113 — Screen Capture / T1125 — Video Capture: Screenshots and custom desktop video recording to surveil operators/environments (notably reconnaissance of POS/back-office staff).

Command and Control

  • T1071.004 — Application Layer Protocol (DNS): C2 over DNS A, OPT, and TXT records.
  • T1008 — Fallback Channels: Harpy backdoor falls back to DNS if HTTP C2 fails.
  • T1102.002 — Web Service (Bidirectional): Google Docs, Google Scripts, and Pastebin for C2.
  • T1572 — Protocol Tunneling: OpenSSH reverse tunnels for C2/egress.
  • T1219 — Remote Access Tools: Abuses Atera RMM to download/run malware.
  • T1105 — Ingress Tool Transfer: Pulls additional payloads via PowerShell shellcode stagers.

Exfiltration

  • T1567.002 — Exfiltration to Cloud Storage: Stolen data exfiltrated to MEGA file-sharing.

Impact

  • T1486 — Data Encrypted for Impact: Deploys ransomware as the end objective, including Darkside encrypting ESXi virtual-disk volumes; affiliate deployment of Cl0p, Black Basta, REvil, etc.

Signature tooling & malware

  • Carbanak / Anunak (S0030)custom flagship backdoor; full-featured RAT for control, recon, and POS data theft.
  • POWERTRASH (a.k.a. Powertrash)custom heavily obfuscated PowerShell loader that reflectively loads PE payloads in memory (a strong FIN7 fingerprint; ~50 samples tracked 2020–2022).
  • Lizar / Diceloader / IceBot (S0681)custom modular post-exploitation backdoor / loader.
  • JSS Loader (S0648)custom .NET/JS-based loader for follow-on payloads.
  • GRIFFON (S0417)custom JavaScript-based modular implant/recon backdoor.
  • HALFBAKED (S0151), POWERSOURCE/DNSMessenger (S0145), TEXTMATE (S0146), SQLRat (S0390)custom loaders/backdoors from the spearphishing/POS era.
  • BOOSTWRITE (S0415) / RDFSNIFFER (S0416)custom; BOOSTWRITE is a DLL-hijack loader, RDFSNIFFER tampers with the Aloha Command Center RDP client (POS targeting).
  • Pillowmint (S0517)custom POS RAM-scraper for payment-card data.
  • AvNeutralizer / AuKillcustom EDR/AV-killer (kernel driver abuse) marketed/sold on criminal forums.
  • Cobalt Strike (S0154), PowerSploit (S0194), Mimikatz (S0002), AdFind (S0552), CrackMapExec (S0488), Core Impact, Impacket, OpenSSH, TightVNC, Atera RMMpublic / commercial / cracked offensive and dual-use tooling.
  • Ransomware payloads: Darkside / BlackMatter (own RaaS); affiliate use of Maze (S0449), REvil (S0496), Cl0p, Black Basta, ALPHV/BlackCat, LockBit; SystemBC (S9001) as a proxy/loader.

Emulation guidance (Decepticon)

Authorized use only: Execute these emulation steps strictly inside the agreed engagement scope and rules of engagement, with written authorization, against in-scope assets only — never against third parties or production data you are not cleared to touch. Use benign substitutes for destructive impact actions.

Map FIN7's signature chain to Decepticon's own capabilities:

  • Initial access (phishing IT staff) — T1566.001/.002, T1204, T1583.001: Use Decepticon's phishing/social-engineering workflow to stand up a typosquatted "IT tool" landing page (mimic Advanced IP Scanner) and deliver a benign tracked payload via a cloud-share link (Dropbox-style). Prioritize recipients with admin rights, mirroring FIN7's IT-staff focus. Stage decoy infra via the cloud skills (look-alike domain + object-storage hosting, T1583.006/T1608.001).
  • BadUSB drop — T1091/T1674: If physical-access testing is in scope, emulate the mailed-USB vector with a HID/keystroke-injection device that triggers a benign PowerShell beacon download. Otherwise document the vector without execution.
  • Loader & in-memory execution — T1059.001/T1620/T1027: Use the bash/PowerShell tooling plus the defense-evasion skill to reproduce a POWERTRASH-style obfuscated reflective PE loader (string fragmentation, junk code, in-memory load) delivering your C2 stage — do not drop a payload to disk.
  • C2 — T1071.004/T1102.002/T1572/T1219: Drive C2 through the c2/sliver skill. Emulate FIN7's channel diversity: an HTTP(S) Sliver listener, a DNS listener (mirrors T1071.004), web-service C2 (mirror T1102.002), with OpenSSH reverse-tunnel egress (T1572) and an RMM-style channel as a fallback. Configure non-standard ports (T1571) to test egress controls.
  • Discovery & cred access — T1087.002/T1069.002/T1558.003/T1003: Use the Active Directory skills to enumerate domain admins/groups (net group, csvde-equivalent), then perform Kerberoasting and credential extraction (Mimikatz-equivalent via the AD/cred-access tooling) exactly as FIN7 chains recon → Kerberoast → lateral movement.
  • Lateral movement — T1021.001/.004/.005/T1572: Use the lateral-movement skill for RDP, SSH, VNC, and Impacket/CrackMapExec-style remote execution to traverse to high-value hosts (Exchange, hypervisors, file servers).
  • Defense evasion / EDR tampering — T1562.001/T1553.002: With the defense-evasion skill, emulate AvNeutralizer-style EDR-tamper detection testing (e.g., attempt to stop/blind the agreed test sensor in a controlled VM) and code-signing/masquerading of artifacts — never disable production security controls outside an isolated test host.
  • Exchange/ProxyShell + Auto-SQLi — T1190/T1195.002: If web-facing assets are in scope, emulate the "Checkmarks" pattern with the cloud/web-exploitation tooling (ProxyShell-class checks, SQLi probing) against the designated test target only.
  • Impact (ransomware) — T1486: Do not encrypt real data. Emulate the BGH end-state with a benign canary "ransom" routine (touch marker files / rename in an isolated directory) and stage a simulated exfil-then-encrypt to MEGA-like storage (T1567.002) to exercise blue-cell DLP and backup detection.

Detection & defense

  • Phishing of privileged IT staff (T1566/T1204): Detect typosquatted domains impersonating admin tools (Advanced IP Scanner, etc.); alert on cloud-share downloads of EXE/MSI by IT-admin accounts; block/inspect newly registered look-alike domains; enforce mark-of-the-web and macro/DDE disablement on Office.
  • BadUSB / HID injection (T1091/T1674): Enforce USB device-control policy; alert on a "keyboard" enumerating immediately followed by PowerShell network egress.
  • POWERTRASH / in-memory loaders (T1059.001/T1620/T1027): Enable PowerShell Script Block Logging, AMSI, and Module Logging; alert on reflective Assembly::Load / in-memory PE patterns, certutil decoding, and heavily obfuscated/fragmented script content.
  • Persistence (T1547.001/T1543.003/T1053.005/T1569.002): Monitor new Run keys, new services, scheduled tasks with masquerading names ("AdobeFlashSync"), and sc start sshd / unexpected sshd services on Windows.
  • Lateral movement & cred access (T1021/T1558.003/T1003): Alert on Kerberoast TGS-REQ bursts (RC4), LSASS access, Impacket/CrackMapExec patterns, and anomalous RDP/SSH/VNC between workstations and servers; deploy honey SPNs.
  • C2 (T1071.004/T1102.002/T1572/T1219): Inspect/limit outbound DNS (large TXT/OPT volume), monitor for SSH reverse tunnels from non-admin hosts, baseline use of Google Docs/Scripts/Pastebin and Atera/other RMM agents; block unsanctioned RMM.
  • EDR tampering (T1562.001): Enable tamper protection; monitor for vulnerable-driver loads (e.g., ProcLaunchMon.sys, Process Explorer driver) and BYOVD patterns; alert on security-service stop/kill events.
  • Exploitation (T1190/T1210): Patch Exchange ProxyShell (CVE-2021-34473/-34523/-31207) and ZeroLogon (CVE-2020-1472); monitor Exchange for webshell drops and Auto-SQLi/SQLMap signatures.
  • Impact (T1486/T1567.002): Protect/segment ESXi management; immutable, offline backups; DLP and egress monitoring for MEGA/cloud-storage bulk uploads; alert on mass-rename/encryption file events.

Sources

Repository
PurpleAILAB/Decepticon
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.