CSIDB logo
Threat actor

FIN7

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
0 incidents
Sources
35 sources
First seen
-
Last seen
-
Updated
2026-08-01 06:24
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

FIN7 is a financially motivated threat actor also known by the aliases Cobalt Group and Carbon Spider, with its operational base identified as Russia in the available context. The group has been active since at least mid‑2015 and is frequently associated by researchers with the Carbanak backdoor, which is also referred to as Cobalt in some reporting. Their primary motivation is financial gain, as explicitly noted in the source material describing them as a financially‑motivated threat group that targets banks and point‑of‑sale terminals for monetary profit.

The actor’s typical targets include banks and point‑of‑sale (POS) terminals belonging to European and United States companies across various industry sectors, a focus that has been consistently reported in the sources. In addition to traditional financial institutions, FIN7 has demonstrated interest in ATM manufacturers, specifically targeting NCR Corporation through tools designed to hijack the NCR Aloha Command Center Client application. Their strategic objective is to gain unauthorized access to financial systems in order to steal funds or facilitate fraudulent transactions, rather than pursuing espionage or disruption as primary goals.

Notable tactics, techniques and procedures described in the material include the use of the BOOSTWRITE in‑memory malware loader, which employs a DLL search order hijacking technique to pull malicious DLLs into memory, download an initialization vector and decryption key, and then decrypt and execute payloads without writing them to disk. One of the payloads delivered by BOOSTWRITE is the RDFSNIFFER remote access trojan, which injects itself into the legitimate NCR RDFClient process to monitor or alter connections, enabling man‑in‑the‑middle attacks and allowing the upload, download, execution or deletion of arbitrary files. The group also relies on phishing campaigns, as evidenced by a post‑arrest operation that targeted bank employees in Russia and Romania, and they have historically relied on the Carbanak backdoor for long‑term access to victim networks.

Attribution information links FIN7 to the Carbanak and Cobalt designations used by security researchers, and the group’s location is noted as Russia in the provided threat actor context. Although several members have been arrested, analyses from Arbor Networks and Kaspersky’s Global Research and Analysis Team indicate that the organization remains active, continuing to employ the same tactics, tools and procedures observed in earlier campaigns. Representative operations cited in the sources include the compromise of banks and POS systems across Europe and the United States using Carbanak, the intrusion into NCR’s ATM‑related software via BOOSTWRITE and RDFSNIFFER, and the phishing effort directed at Russian and Romanian bank employees that surfaced after earlier arrests. These activities illustrate the group’s persistent focus on financial theft through a combination of custom malware, legitimate software abuse and social engineering.

Incidents

Attributed incidents are available to members.

0 incidents

Sources

Sources available to members: 35 sources.

CSIDB