logo

FIN7 Cybercrime Group: Evolution from POS Attacks to Ransomware-as-a-Service (RaaS) Operations

ID: b682f4a4-190b-50e1-8ef4-a469be1b8a04

STIX ID: report--b682f4a4-190b-50e1-8ef4-a469be1b8a04

Feed Name: Resources-2

Threat Score
85/100

Date Published: 2025-10-24

Date Updated: 2026-07-22

Author: Picus Labs

...
...

FIN7 (aka Carbon Spider / GOLD NIAGARA) is a long-running, financially motivated cybercriminal group that evolved from large-scale POS card‑skimming campaigns into targeted ‘big‑game’ ransomware and supply‑chain attacks; the report details its multi-stage, fileless execution techniques (PowerShell, VBS, JavaScript), custom obfuscation and junk‑code tactics, use of fraudulent front companies to recruit contractors, notable intrusions and timelines, ATT&CK TTP mappings, and specific indicators (MD5s, commands) and behaviors for detection and simulation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.