Cyber Threat Report: 'Threat Group FIN7 Targets the U.S. Automotive Industry'

Report Author BlackBerry Research and Intelligence Team
Publication Date 2024-04-17
Original Reporting Source
Related Intrusion Sets ALPHV Blackcat Ransomware Group , FIN7
Victim Sectors Automotive

In late 2023, BlackBerry analysts discovered a targeted attack by FIN7 on a U.S. automotive manufacturer, exploiting IT employees with higher administrative rights using a fake IP scanning tool to deploy the Anunak backdoor. The attack involved a multi-stage execution process using spear-phishing emails, malicious URLs, and a series of downloads and decrypts to ultimately deliver the Anunak payload. According to the researchers, FIN7, also known as Carbon Spider, ELBRUS and Sangria Tempest, has shifted focus from widespread attacks to precise targeting of large entities, deploying ransomware as the final payload. The post also suggests that FIN7 is affiliated with other groups including GOLD NIAGARA, ALPHV and BlackCat. The post details tactics, techniques and procedures (TTPs), Indicators of Compromise (IoCs) and recommendations for mitigation.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques

ATT&CK ID Title Associated Tactics
T1057 Process Discovery Discovery
T1087.002 Domain Account Discovery
T1059.001 PowerShell Execution
T1562.004 Disable or Modify System Firewall Defense Evasion
T1090 Proxy Command and Control
T1543.003 Windows Service Persistence, Privilege Escalation
T1566.002 Spearphishing Link Initial Access
T1608.005 Link Target Resource Development
T1069.002 Domain Groups Discovery
T1564.001 Hidden Files and Directories Defense Evasion
T1027 Obfuscated Files or Information Defense Evasion
T1204.002 Malicious File Execution
T1583.001 Domains Resource Development
T1041 Exfiltration Over C2 Channel Exfiltration
T1124 System Time Discovery Discovery
T1033 System Owner/User Discovery Discovery
T1053.005 Scheduled Task Execution, Persistence, Privilege Escalation
T1082 System Information Discovery Discovery