Adversary-emulation profile for FIN7 (G0046; aka Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS) — a financially motivated Russian-speaking crime group, mapping its TTPs to Decepticon tooling for authorized red-team emulation.
49
53%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/fin7-carbanak/SKILL.mdFIN7 (MITRE ATT&CK G0046; also tracked as Carbanak, Carbon Spider, Sangria Tempest, GOLD NIAGARA, ELBRUS, and ITG14) is one of the most prolific and best-documented financially motivated cybercrime groups, active since at least 2013. Originally infamous for large-scale point-of-sale (POS) intrusions to steal payment-card data — operating behind the front company "Combi Security" — the group pivoted to "big game hunting" ransomware around 2020, running its own Darkside/BlackMatter Ransomware-as-a-Service and acting as an affiliate/tooling supplier for REvil, Cl0p, Black Basta, ALPHV/BlackCat, LockBit, and others. FIN7 is characterized by disciplined operational tradecraft: convincing social engineering (including spearphishing of IT staff and physically mailed BadUSB drives), heavily obfuscated custom loaders (POWERTRASH), signature backdoors (Carbanak/Anunak, Lizar/Diceloader), purchased/cracked commercial tooling (Cobalt Strike, Core Impact), and a productized EDR-killer (AvNeutralizer/AuKill) sold on criminal forums.
ProcLaunchMon.sys/Process Explorer driver) and sold it on criminal forums; used by Black Basta and later multiple ransomware crews. (SentinelOne, IBM)advanced-ip-sccanner[.]com → myipscanner[.]com), a Dropbox-hosted WsTaskLoad.exe, POWERTRASH, the Anunak/Carbanak backdoor, and OpenSSH for persistence. (BlackBerry / BleepingComputer)Reflection.Assembly::Load (and in-memory PE loading via POWERTRASH).sc start sshd.certutil to decode PowerShell; XOR-deobfuscation routines.ProcLaunchMon.sys / Process Explorer driver). (SentinelOne; mapped to T1562.001)attrib +h to hide an SSH folder; .txt-concealed PowerShell.sleep.exe; loader masquerades as WsTaskLoad.exe.csvde.exe.net group to enumerate domain groups.tasklist /v via WsTaskLoad.exe / PowerShell.csvde.exe and WsTaskLoad for host enumeration.cmd.exe /C quser for active sessions.net time via PowerShell script.Authorized use only: Execute these emulation steps strictly inside the agreed engagement scope and rules of engagement, with written authorization, against in-scope assets only — never against third parties or production data you are not cleared to touch. Use benign substitutes for destructive impact actions.
Map FIN7's signature chain to Decepticon's own capabilities:
net group, csvde-equivalent), then perform Kerberoasting and credential extraction (Mimikatz-equivalent via the AD/cred-access tooling) exactly as FIN7 chains recon → Kerberoast → lateral movement.Assembly::Load / in-memory PE patterns, certutil decoding, and heavily obfuscated/fragmented script content.sc start sshd / unexpected sshd services on Windows.ProcLaunchMon.sys, Process Explorer driver) and BYOVD patterns; alert on security-service stop/kill events.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.