logo

FIN7 targets American automaker’s IT staff in phishing attacks

ID: b936daa4-1aa7-5700-8bd3-b45973b821a4

STIX ID: report--b936daa4-1aa7-5700-8bd3-b45973b821a4

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-17

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

FIN7 targeted privileged IT employees at a large U.S. automaker with spear-phishing that led to a typosquatted Advanced IP Scanner installer (WsTaskLoad.exe) which executed a multi-stage loader (including WAV/DLL/shellcode) to decrypt dmxl.bin and deploy the Anunak backdoor; researchers observed LoLBas, obfuscated PowerShell ('PowerTrash'), scheduled tasks and OpenSSH usage, though the intrusion did not progress beyond the initial host.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.