This financially-motivated advance persistence threat group is one of the most prolific cyber threat actor gangs in the world which has added ransomware to its attack arsenal. The organization gained infamy in 2014 after it stole a total of $1 billion from over 100 companies around the world. REvil has also been used by the threat group until they created their own RaaS (Ransomware as a Service), Darkside. The group has been behind many notorious hacks of 2018 and has also been linked to Ryuk. Researchers think FIN7 has a well-funded research and testing division that enables it avoid detection by antivirus and scanners.
The gang leverages PowerShell to automate tasks and maintain configurations throughout all of its intrusions, including a new backdoor named PowerPlant. In addition to the usual phishing techniques, its initial access methods have expanded to encompass software supply chain breach and the exploitation of stolen credentials.