All actors

FIN7

Also reported as ITG14, GOLD NIAGARA, Carbon Spider, ELBRUS, Sangria Tempest and 7 other names. Linked to Russia by one source.

Reports
860
Last reported
Known CVEs
386
Techniques in ATT&CK
67
Origin
Russia
ID
G0046
Sources
ATT&CKETDA
Merge evidence
1 alias match

Reports per quarter

  1. 2015 Q1: 3 reports
  2. 2015 Q2: no reports
  3. 2015 Q3: 1 report
  4. 2015 Q4: 1 report
  5. 2016 Q1: 2 reports
  6. 2016 Q2: no reports
  7. 2016 Q3: 2 reports
  8. 2016 Q4: 1 report
  9. 2017 Q1: 2 reports
  10. 2017 Q2: 10 reports
  11. 2017 Q3: 3 reports
  12. 2017 Q4: 9 reports
  13. 2018 Q1: 1 report
  14. 2018 Q2: 3 reports
  15. 2018 Q3: 9 reports
  16. 2018 Q4: 6 reports
  17. 2019 Q1: 11 reports
  18. 2019 Q2: 19 reports
  19. 2019 Q3: 4 reports
  20. 2019 Q4: 11 reports
  21. 2020 Q1: 18 reports
  22. 2020 Q2: 19 reports
  23. 2020 Q3: 24 reports
  24. 2020 Q4: 40 reports
  25. 2021 Q1: 44 reports
  26. 2021 Q2: 70 reports
  27. 2021 Q3: 79 reports
  28. 2021 Q4: 63 reports
  29. 2022 Q1: 63 reports
  30. 2022 Q2: 69 reports
  31. 2022 Q3: 45 reports
  32. 2022 Q4: 18 reports
  33. 2023 Q1: 17 reports
  34. 2023 Q2: 10 reports
  35. 2023 Q3: 17 reports
  36. 2023 Q4: 16 reports
  37. 2024 Q1: 9 reports
  38. 2024 Q2: 12 reports
  39. 2024 Q3: 20 reports
  40. 2024 Q4: 14 reports
  41. 2025 Q1: 7 reports
  42. 2025 Q2: 9 reports
  43. 2025 Q3: 8 reports
  44. 2025 Q4: 5 reports
  45. 2026 Q1: 4 reports
  46. 2026 Q2: 62 reports
Dated reports, 2015 Q1 to 2026 Q2.

Techniques seen in the last two years

Show all 272 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 15 techniques Show fewer

CVEs named in reports

Show all 386 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. BlackCat (Malware Family)

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  3. Vjw0rm (Malware Family)

    date ORKL added it fromORKL

Show all 860 reports Show fewer
  1. Ave Maria (Malware Family)

    date ORKL added it fromORKL

  2. FlawedAmmyy (Malware Family)

    date ORKL added it fromORKL

  3. QakBot (Malware Family)

    date ORKL added it fromORKL

  4. REvil (Malware Family)

    date ORKL added it fromORKL

  5. Meterpreter (Malware Family)

    date ORKL added it fromORKL

  6. Dridex (Malware Family)

    date ORKL added it fromORKL

  7. PyXie (Malware Family)

    date ORKL added it fromORKL

  8. Griffon (Malware Family)

    date ORKL added it fromORKL

  9. DarkSide (Malware Family)

    date ORKL added it fromORKL

  10. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  11. Ryuk (Malware Family)

    date ORKL added it fromORKL

  12. BlackMatter (Malware Family)

    date ORKL added it fromORKL

  13. BlackMatter (Malware Family)

    date ORKL added it fromORKL

  14. Andromeda (Malware Family)

    date ORKL added it fromORKL

  15. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  16. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  17. ALPHV-BlackCat ransomware family becoming more dangerous

    date in the title fromORKL

  18. RedSense

    Malpedia library date fromORKL

  19. JSSLoader- the shellcode edition

    date in the title fromORKL

  20. RedSense

    Malpedia library date fromORKL

  21. CERT-UA

    Malpedia library date fromORKL

  22. CERT-UA

    Malpedia library date fromORKL

  23. RedSense

    Malpedia library date fromORKL

  24. Russian cyber attack campaigns and actors.pdf

    file creation date fromORKL

  25. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  26. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  27. RedSense

    Malpedia library date fromORKL

  28. New JSSLoader Trojan Delivered Through XLL Files

    date in the title fromORKL

  29. CERT-UA

    Malpedia library date fromORKL

  30. Excel Add-ins Deliver JSSLoader Malware

    date in the title fromORKL

  31. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  32. 2021trends.pdf

    Malpedia library date fromORKL

  33. RedSense

    Malpedia library date fromORKL

  34. FIN7 Uses Flash Drives to Spread Remote Access Trojan

    date in the title fromORKL

  35. FINDING BEACONS IN THE DARK 1650728751599

    Malpedia library date BlackBerry fromORKLCCS '25 data

  36. FIN7 Tools Resurface in the Field – Splinter or Copycat-

    date in the title fromORKL

  37. Understanding the Windows JavaScript Threat Landscape

    date in the title fromORKL

  38. CARBON SPIDER Embraces Big Game Hunting, Part 2

    date in the title fromORKL

  39. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  40. FIN7 Recruits Talent For Push Into Ransomware

    date in the title fromORKL

  41. RedSense

    Malpedia library date fromORKL

  42. eset_threat_report_t22021

    file creation date fromORKL

  43. Report2021ThreatHunting

    file creation date fromORKL

  44. CARBON SPIDER Embraces Big Game Hunting, Part 1

    date in the title fromORKL

  45. FIN7 still active

    date in the title fromORKL

  46. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  47. REvil-ution – A Persistent Ransomware Operation

    date in the title fromORKL

  48. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  49. The Evolution of PINCHY SPIDER from GandCrab to REvil

    date in the title fromORKL

  50. JSSLoader- Recoded and Reloaded

    date in the title fromORKL

  51. Ransomware Actors Evolved Their Operations in 2020

    date in the title fromORKL

  52. eset_threat_report_t12021

    file creation date fromORKL

  53. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  54. CTIR_casestudy_2.pdf

    file creation date fromORKL

  55. CTIR_casestudy_1.pdf

    file creation date fromORKL

  56. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  57. Carbanak and FIN7 Attack Techniques

    date in the title fromORKL

  58. FIN7 'technical guru' sentenced to 10 years in prison

    date in the title fromORKL

  59. mtrends-2021

    file creation date fromORKL

  60. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  61. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  62. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  63. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  64. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  65. [Morphisec]_The_Evolution_of_the_FIN7_JssLoader

    Malpedia library date fromORKL

  66. Collaboration Between FIN7 and the RYUK Group

    date in the CCS '25 data Truesec fromORKLCCS '25 data

  67. Russian cyber attack campaigns and actors

    date in the title fromORKL

  68. ESET_Threat_Report_Q32020

    file creation date fromORKL

  69. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  70. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  71. CERTFR-2020-CTI-009

    file creation date fromORKL

  72. CrimeOps- The Operational Art of Cyber Crime

    date in the title fromORKL

  73. OpBlueRaven- Unveiling Fin7-Carbanak - Part 1 - Tirion

    date in the title fromORKL

  74. ESET_Threat_Report_Q22020

    file creation date fromORKL

  75. Pillowmint- FIN7’s Monkey Thief

    date in the title fromORKL

  76. Russian Cyber Attack Campaigns and Actors - Threat Research

    file creation date fromORKL

  77. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  78. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  79. Would You Exchange Your Security for a Gift Card-

    date in the title fromORKL

  80. Talks - BrightTALK

    Malpedia library date fromORKL

  81. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  82. mtrends-2020

    file creation date fromORKL

  83. 2020.02.22_APT_threat_report_2019_CN_version

    Malpedia library date fromORKL

  84. Introducing BIOLOAD- FIN7 BOOSTWRITE’s Lost Twin

    date in the title fromORKL

  85. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  86. Mahalo_FIN7

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  87. ASEC_REPORT_vol.96_ENG

    date in the CCS '25 data AhnLab fromORKLCCS '25 data

  88. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  89. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  90. FIN7.5_ the infamous cybercrime rig “FIN7” continues its activities

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  91. ATMitch_ New Evidence Spotted In The Wild

    date in the CCS '25 data Yoroi fromORKLCCS '25 data

  92. CARBANAK Week Part Four: The CARBANAK Desktop Video Player

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  93. CARBANAK Week Part One: A Rare Occurrence

    date in the CCS '25 data FireEye fromORKLCCS '25 data

  94. CARBANAK Week Part One- A Rare Occurrence

    date in the title fromORKL

  95. rpt-mtrends-2019.pdf

    file creation date fromORKL

  96. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  97. FIN7 Revisited- Inside Astra Panel and SQLRat Malware

    date in the title fromORKL

  98. Report2019GlobalThreatReport

    file creation date fromORKL

  99. rpt-mtrends-2019

    file creation date fromORKL

  100. Identifying Cobalt Strike team servers in the wild

    date in the title fromORKL

  101. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  102. 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version

    file creation date fromORKL

  103. ENISA Threat Landscape Report 2018

    file creation date fromORKL

  104. FIN7 Not Finished - Morphisec Spots New Campaign

    date in the title fromORKL

  105. FIN7 Not Finished – Morphisec Spots New Campaign

    date in the title fromORKL

  106. Three Carbanak cyber heist gang members arrested

    date in the title fromORKL

  107. Goldfin Alert | Accenture

    file creation date fromORKL

  108. Arrests Put New Focus on CARBON SPIDER Adversary Group

    date in the title fromORKL

  109. Anunak: Apt Against Financial Institutions

    Malpedia library date Group-IB, FOX-IT fromORKLCCS '25 data

  110. Inside the Response of a Unique CARBANAK Intrusion

    file creation date RSA fromORKL

  111. The Shadows of Ghosts: Inside the Response of a... | RSA Link

    date in the CCS '25 data RSA fromORKLCCS '25 data

  112. The Carbanak/Fin7 syndicate

    file creation date RSA fromORKL

  113. Muddying the Water: Targeted Attacks in the Middle East

    file creation date fromORKL

  114. Muddying the Water- Targeted Attacks in the Middle East

    date in the title fromORKL

  115. Inside the Response of a Unique CARABANK Intrusion

    file creation date fromORKL

  116. FIN7 Dissected- Hackers Accelerate Pace of Innovation

    date in the title fromORKL

  117. CCleanup

    date in the CCS '25 data Symantec fromORKLCCS '25 data

  118. Behind the CARBANAK Backdoor

    date in the title fromORKL

  119. FIN7 Takes Another Bite at the Restaurant Industry

    date in the title fromORKL

  120. FIN7 Evolution and the Phishing LNK

    date in the title fromORKL

  121. New Carbanak / Anunak Attack Methodology

    date in the CCS '25 data Trustwave fromORKLCCS '25 data

  122. Visa Alert and Update on the Oracle Breach

    date in the CCS '25 data Brian Krebs fromORKLCCS '25 data

  123. Carbanak Oracle Breach

    date in the CCS '25 data Visa fromCCS '25 data

  124. proofpoint-threat-insight-carbanak-group-en

    date in the CCS '25 data Proofpoint fromORKLCCS '25 data

  125. Russian financial cybercrime_ how it works - Securelist

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  126. Carbanak is packing new guns

    date in the CCS '25 data ESET fromORKLCCS '25 data

  127. Carbanak

    Malpedia library date fromORKL

  128. Carbanak

    date in the title fromORKL

  129. Carbanak_APT_eng.pdf

    Malpedia library date Kaspersky fromORKLCCS '25 data

Newest first. Details opens the report in Explore.