home.social

#fin7 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fin7, aggregated by home.social.

fetched live
  1. One Step Ahead in Cyber Hide-and-Seek: Automating Malicious Infrastructure Discovery With Graph Neural Networks
    #FIN7
    unit42.paloaltonetworks.com/gr

  2. The Russian cybercrime group FIN7 ran a network of fake AI undressing sites that delivered credential stealing malware to those who uploaded pictures. I gotta say, this is one group of cybercrime victims that I don't feel sorry for.

    silentpush.com/blog/fin7-malwa

    #FIN7 #Russia #Cybercrime #NetSupport #NetSupportRAT #RAT #Malware #CredentialTheft #AI #Deepfake #Deepfakes #DeepNude #DeepNueds #SilentPush

  3. Additionally, our report takes a look at landing pages impersonating popular software websites, masquerading malware as legitimate installers.

    Multiple intrusion sets like #FIN7 and #BlackCat affiliates used this distribution technique.

  4. Onapsis and Flashpoint produced a 29 report on the cyber threat landscape for SAP applications over the past 4 years. SAP is the world's largest provider of enterprise application software. The report highlights the material risk of SAP ransomware attacks and the growing maturity of cybercriminal capabilities. Their appendices at the bottom list known SAP vulnerabilities (if they're on CISA's Known Exploited Vulnerabilities (KEV) Catalog), as well as MITRE ATT&CK techniques associated with SAP exploitation, and threat actors (financially motivated and ransomware groups) targeting SAP-using organizations. 🔗 (PDF) go.onapsis.com/threat-report/c

    #SAP #vulnerability #cybercrime #threatintel #FIN13 #CobaltSpider #FIN7 #BlackCat #AlphV #BianLian #BlackBasta

  5. BlackBerry reports on a spear-phishing campaign in late 2023 by the financially motivated FIN7 targeting a large U.S. automotive manufacturer. They targeted IT department employees with admin rights using a free IP scanning tool, to deloy Anunak backdoor. FIN7 performed living off the land binaries, scripts and libraries (lolbas). MITRE ATT&CK TTPs and IOC provided. 🔗 blogs.blackberry.com/en/2024/0

    #FIN7 #threatintel #cybercrime #IOC