{"id":2731,"date":"2021-05-15T21:58:18","date_gmt":"2021-05-16T02:58:18","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=2731"},"modified":"2021-05-15T21:58:19","modified_gmt":"2021-05-16T02:58:19","slug":"fin7-a-dangerous-group-of-hackers","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/","title":{"rendered":"FIN7, a dangerous group of hackers"},"content":{"rendered":"\n<p>This group of hackers called Fin7 has been around for a long time, as it is believed to be behind attacks targeting the US retail, restaurant and hospitality sectors since mid-2015, working closely together and sharing tools and methods with the famous Carbanak group.<\/p>\n\n\n\n<p>In 2018, alleged leaders of the organization had been arrested, but unfortunately in 2019 Kaspersky Lab researchers detected a series of new attacks by the same groups using the Griffon malware. According to company experts, Fin7 could have expanded the number of groups operating under its umbrella, increased the sophistication of its methods, and even positioned itself as a legitimate security provider to recruit professional employees and trick them into helping them steal. financial assets.<\/p>\n\n\n\n<p>Now in December 2020 FIN7 began to carry out a campaign to distribute a tool called JSSLoader, considered a remote access Trojan (RAT) with multiple capabilities implemented for the capture and exfiltration of confidential information. The attack vector used by this group was the sending of e-mails with themes that manage to capture the attention of users and that contain links to download malicious files from a private SharePoint repository.<\/p>\n\n\n\n<p>The downloaded files were Visual Basic Script (VBS) executables that download a JSSLoader module, which is stored in the% temp% directory and executes it through a scheduled task created on the computer, in addition, it was observed that this RAT uses a PowerShell script called DiceLoader to download Cobalt Strike, a tool used by cybercriminals to exploit vulnerabilities in a system, in order to gain access to a target network. Fin7 is undoubtedly active and care must be taken especially in the business sector, since these tend to target companies to ask for huges sums of money.<\/p>\n\n\n\n<p>In addition, this group created a fake company that is registered on the server that Fin7 uses as a Command and Control Center. This bogus business has been used to recruit freelance vulnerability researchers, software developers, and interpreters through legitimate online job sites. It seems that some of the people who work in these fake companies did not suspect that they were involved in a cybercriminal business.<\/p>\n\n\n\n<p>See also:<br><a href=\"https:\/\/truxgoservers.com\/blog\/pyvil-rat-new-trojan-from-the-evilnum-group\/\">PyVil RAT \u2013 New Trojan from the Evilnum group<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/milton-group-the-scam-company-that-gave-promise\/\">Milton Group \u2013 the scam company that gave promise<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This group of hackers called Fin7 has been around for a long time, as it is believed to be behind attacks targeting the US retail, restaurant and hospitality sectors since mid-2015, working closely together and sharing tools and methods with the famous Carbanak group. In 2018, alleged leaders of the organization had been arrested, but [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2732,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-2731","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>FIN7, a dangerous group of hackers - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Hacker groups have always been there looking for new ways to steal information or money, today we will talk about the group called Fin7.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FIN7, a dangerous group of hackers - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Hacker groups have always been there looking for new ways to steal information or money, today we will talk about the group called Fin7.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-16T02:58:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-05-16T02:58:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/hacker-group.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"FIN7, a dangerous group of hackers\",\"datePublished\":\"2021-05-16T02:58:18+00:00\",\"dateModified\":\"2021-05-16T02:58:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/\"},\"wordCount\":374,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/hacker-group.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/\",\"name\":\"FIN7, a dangerous group of hackers - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/hacker-group.jpg\",\"datePublished\":\"2021-05-16T02:58:18+00:00\",\"dateModified\":\"2021-05-16T02:58:19+00:00\",\"description\":\"Hacker groups have always been there looking for new ways to steal information or money, today we will talk about the group called Fin7.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/hacker-group.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/05\\\/hacker-group.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/fin7-a-dangerous-group-of-hackers\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FIN7, a dangerous group of hackers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FIN7, a dangerous group of hackers - Truxgo Server Blog","description":"Hacker groups have always been there looking for new ways to steal information or money, today we will talk about the group called Fin7.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/","og_locale":"es_MX","og_type":"article","og_title":"FIN7, a dangerous group of hackers - Truxgo Server Blog","og_description":"Hacker groups have always been there looking for new ways to steal information or money, today we will talk about the group called Fin7.....","og_url":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-05-16T02:58:18+00:00","article_modified_time":"2021-05-16T02:58:19+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/hacker-group.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"FIN7, a dangerous group of hackers","datePublished":"2021-05-16T02:58:18+00:00","dateModified":"2021-05-16T02:58:19+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/"},"wordCount":374,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/hacker-group.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/","url":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/","name":"FIN7, a dangerous group of hackers - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/hacker-group.jpg","datePublished":"2021-05-16T02:58:18+00:00","dateModified":"2021-05-16T02:58:19+00:00","description":"Hacker groups have always been there looking for new ways to steal information or money, today we will talk about the group called Fin7.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/hacker-group.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/05\/hacker-group.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/fin7-a-dangerous-group-of-hackers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"FIN7, a dangerous group of hackers"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2731","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=2731"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2731\/revisions"}],"predecessor-version":[{"id":2741,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/2731\/revisions\/2741"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/2732"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=2731"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=2731"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=2731"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}