Tag: FIN7

FIN7, FIN8, and Others Use Ragnar Loader for Persistent Access and Ransomware Operations
News

FIN7, FIN8, and Others Use Ragnar Loader for Persistent Access and Ransomware Operations

Threat hunters have revealed that a "sophisticated and evolving malware toolkit" known as Ragnar Loader is utilized by a number of ransomware and cybercrime organizations, including Ruthless Mantis (formerly REvil), FIN7, FIN8, and Ragnar Locker (also known as Monstrous Mantis). According to a statement sent to The Hacker News by the Swiss cybersecurity firm PRODAFT, Ragnar Loader is essential for maintaining access to compromised computers and assisting attackers in remaining in networks for extended operations. Although the Ragnar Locker group is associated with it, it's unknown if they actually own it or if they only rent it out. We do know that its developers are continuously adding new features, which makes it more difficult to detect and more modular read more about FIN7 FIN8 ...
FIN7 Group Advertises Security-Bypassing Tool on Dark Web Forums
News

FIN7 Group Advertises Security-Bypassing Tool on Dark Web Forums

FIN7, a financially driven threat actor, has been seen advertising a tool known to be utilized by ransomware gangs like Black Basta on different underground forums under various pseudonyms. The cybersecurity company SentinelOne said in a report provided with The Hacker News that "AvNeutralizer (aka AuKill), a highly specialized tool developed by FIN7 to tamper with security solutions, has been marketed in the criminal underground and used by multiple ransomware groups." From its beginnings as an attacker of point-of-sale (PoS) terminals, to serving as a ransomware affiliate for now-defunct gangs like REvil and Conti, to the launch of its own ransomware-as-a-service (RaaS) programs DarkSide and BlackMatter, FIN7, an e-crime group of Russian and Ukrainian origin, has been a consistent...
FIN7 Hacker Group Leverages Malicious Google Ads to Deliver NetSupport RAT
News

FIN7 Hacker Group Leverages Malicious Google Ads to Deliver NetSupport RAT

The financially motivated threat actor known as FIN7 has been seen distributing MSIX installers that ultimately lead to the deployment of NetSupport RAT by using malicious Google advertising that mimic reputable firms. According to a report released earlier this week by cybersecurity firm eSentire, the threat actors impersonated well-known organizations, such as AnyDesk, WinSCP, BlackRock, Asana, Concur, The Wall Street Journal, Workable, and Google Meet, using malicious websites. A persistent e-crime outfit that has been operating since 2013, FIN7 (also known as Carbon Spider and Sangria Tempest) first dabbled in attacks aimed at point-of-sale (PoS) devices to steal payment data before refocusing on ransomware campaigns to penetrate large firms. The threat actor has improved its...