Source |
Mandiant |
Identifiant |
8377782 |
Date de publication |
2017-04-24 09:30:00 (vue: 2023-09-01 14:42:16) |
Titre |
FIN7 Evolution et le phishing LNK FIN7 Evolution and the Phishing LNK |
Texte |
FIN7 est un groupe de menaces motivé financièrement qui a été associé à des opérations malveillantes datant de fin 2015. FIN7 est appelée de nombreux vendeurs de «groupe Carbanak», bien que nous n'asquivons pas toute utilisation de la porte dérobée de Carbanak à FIN7.Fireeye a récemment observé un Campagne de phishing de lance FIN7 Ciblage du personnel impliqué dans les dossiers de Securities and Exchange Commission (SEC) des États-Unis dans diverses organisations.
Dans une campagne nouvellement identifiée, FIN7 a modifié leurs techniques de phishing pour mettre en œuvre des mécanismes d'infection et de persistance uniques.Fin7 s'est éloigné de l'armement
FIN7 is a financially-motivated threat group that has been associated with malicious operations dating back to late 2015. FIN7 is referred to by many vendors as “Carbanak Group”, although we do not equate all usage of the CARBANAK backdoor with FIN7. FireEye recently observed a FIN7 spear phishing campaign targeting personnel involved with United States Securities and Exchange Commission (SEC) filings at various organizations.
In a newly-identified campaign, FIN7 modified their phishing techniques to implement unique infection and persistence mechanisms. FIN7 has moved away from weaponized |
Notes |
★★★★
|
Envoyé |
Oui |
Condensat |
2015 all although associated away back backdoor been campaign carbanak commission dating equate evolution exchange filings fin7 financially fireeye from group group” has identified implement infection involved late lnk malicious many mechanisms modified motivated moved newly not observed operations organizations persistence personnel phishing recently referred sec securities spear states targeting techniques threat unique united usage various vendors weaponized “carbanak |
Tags |
Threat
Technical
|
Stories |
|
Move |
|