logo

Mitre ATT&CK™ and the FIN7 Indictment: Lessons for Organizations

ID: b3b12038-47a7-53bd-a9af-0d848cc8565b

STIX ID: report--b3b12038-47a7-53bd-a9af-0d848cc8565b

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2018-08-22

Date Updated: 2026-04-29

...
...

**Executive summary:** This report analyzes the unsealed indictment of the FIN7 criminal group, describing their large-scale, financially motivated campaigns that used targeted social engineering (spearphishing and phone calls), diverse malware delivery (weaponized Office documents, macros, OLE, LNK, PowerShell), persistence and defense-evasion techniques, credential and payment-card theft from POS environments, and likely exfiltration via leased servers; it concludes with mitigation guidance mapped to the MITRE ATT&CK framework.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.