Uptime Hamster: 10d 11h 32mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza FIN7

FIN7

1 incidentes 1 paises 1 sectores apt RU Ultimo: 2026-05-25
Aliases: ATK32, CARBON SPIDER, Calcium, Carbanak, Coreid, ELBRUS, G0008, G0046, GOLD NIAGARA, JokerStash, Sangria Tempest
Ver en IntelTracker → APTTrail →
FIN7 is a financially motivated cybercriminal group that emerged in 2013, initially specializing in payment card data theft through point-of-sale system compromises. The group has significantly evolved since 2020, shifting its focus to high-value targeted intrusions known as "big game hunting" and actively engaging in ransomware operations, including associations with major ransomware families like REvil and DarkSide, and operating its own Ransomware-as-a-Service model. Assessed with high confidence to be of Eastern European origin, with strong ties to Russia and Ukraine, FIN7 distinguishes itself by operating with a sophisticated, business-like organizational structure, even utilizing front companies like Combi Security to recruit personnel and lend an air of legitimacy to its operations. This group has been known for its adaptability, continuous development of custom malware, and effective evasion techniques. Often tracked under aliases such as Carbon Spider, GOLD NIAGARA, and Sangri

Aliases del actor

ATK32CARBON SPIDERCalciumCarbanakCoreidELBRUSG0008G0046GOLD NIAGARAJokerStashSangria Tempest

Actores similares

Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1
Motivacion