logo

FIN7 Cybercrime Group Targeting U.S. Auto Industry with Carbanak Backdoor

ID: b48ef918-e87e-5cec-b9fd-62627e8bb86d

STIX ID: report--b48ef918-e87e-5cec-b9fd-62627e8bb86d

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-18

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

FIN7 conducted a targeted spear-phishing campaign against a large U.S. automotive manufacturer using a fake IP-scanner site that redirected to a Dropbox-hosted executable (WsTaskLoad.exe) which deployed a multi-stage payload culminating in the Carbanak/Anunak backdoor; additional payloads (POWERTRASH) and persistence via OpenSSH were observed, but the infection was detected and the affected system removed before lateral movement or confirmed ransomware deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.