Official ATT&CK groups · sourced comparison
Documented group behavior. Independent vehicle evidence.
Select a known ATT&CK group to inspect its sourced behavior path. A vehicle path appears only when accepted SBOM and canary records bind to that VIN.
FIN7
Also tracked as Carbon Spider · ELBRUS · GOLD NIAGARA · ITG14 · Sangria Tempest
[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of [FIN7](https://attack.mitre.org/groups/G0046) was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, [FIN7](https://attack.mitre.org/groups/G0046) shifted operations to big game hunting (BGH), including use of [REvil](https://attack.mitre.org/software/S0496) ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the [Carbanak](https://attack.mitre.org/groups/G0008) Group, but multiple threat groups have been observed using [Carbanak](https://attack.mitre.org/software/S0030), leading these groups to be tracked separately.(Citation: FireEye FIN7 March 2017)(Citation: FireEye FIN7 April 2017)(Citation: FireEye CARBANAK June 2017)(Citation: FireEye FIN7 Aug 2018)(Citation: CrowdStrike Carbon Spider August 2021)(Citation: Mandiant FIN7 Apr 2022)(Citation: BiZone Lizar May 2021)
Attribution boundary
Public ATT&CK identity and procedure records only. No relationship to Northstar, a customer, supplier, or selected VIN is asserted.
Official identity source
MITRE ATT&CK · G0046- ATT&CK record
- G0046
- Record version
- 4.1
- Created
- Unknown
- Last modified
- Unknown
- Catalogue release
- 19.2
- Replay fixture
- AL-BUILD-TRUST-1.1.0
- Technique overlaps
- 03
- Mapped events
- 10
- Evidence gates
- 14
- Defensive analytics
- 04
Operational sequence assessment
The active MITRE ATT&CK Enterprise release maps FIN7 to T1195.002 Supply Chain Compromise: Compromise Software Supply Chain. Consult the official group record for its cited procedure examples.
Public behavior is a comparison lens · Northstar events below are synthetic · no attribution
Synthetic replay lane · not VIN evidence
Reached and failed counts below evaluate only the fixed Northstar fixture. They cannot open a vehicle path or establish group presence.
NO VIN
Independent VIN gates
Reached
0/8
Failed gates
0/8
Pending
8/8
Coverage gaps
0/8
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
Select a VIN to build this group’s full evidence path.
A VIN supplies the scope for SBOM, release-manifest and canary evidence. Group behavior remains a separate comparison lens.
Select VINExact ATT&CK joins
Public behavior mapped to fixture observations
Technique context retained
T1195.002 is highlighted below. Public group behavior remains separate from synthetic replay evidence.
PATH 01
T1071.004
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps FIN7 to T1071.004 Application Layer Protocol: DNS. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E04 to E04
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0403:00ReconnaissanceDNS resolver
Resolver log — reserved example domain queried
A single lookup for updates.example.net appears in the range resolver log. In this fixture it is benign-looking and unremarkable in isolation.
DEV-JUMP-07
PATH 02
T1195.002
Compromise Software Supply Chain
Initial Access · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps FIN7 to T1195.002 Supply Chain Compromise: Compromise Software Supply Chain. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E08 to E29
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0807:00Build accessCI orchestrator
The adversary waits for a legitimate build
Nothing is forced. The emulation waits for the scheduled build so that every downstream record looks ordinary.
- E1110:00Build interpositionEndpoint telemetry
The helper observes the compiler invocation
The resident helper watches for the expected compiler invocation. Only observation is modelled; no injection, hooking or evasion technique is described or provided.
BLD-WIN-03
- E11A10:30Build interpositionCI orchestrator
Selectivity check — correct product and expected source version
Before touching anything, the emulated helper confirms the job is the intended product (Aurora Gateway Agent) at the expected source version (ns-48f2). This selectivity is why such activity is rare, quiet and hard to find by sampling: unmatched builds are left completely alone, so most build records look perfectly normal.
BLD-WIN-03
- E1514:00Build interpositionCI orchestrator
Produced binary hash differs from the reproducible reference
Output digest sha256:9f41…c7d2 does not match the reference rebuild digest sha256:2a08…41be for commit ns-48f2. This single comparison is the strongest available integrity signal.
BLD-WIN-03
- E1716:00Trusted releaseCI orchestrator
Trusted release — the ordinary workflow accepts the artifact
Tests, approval, signing and publication all proceed normally. Nothing in the pipeline is bypassed, which is exactly why the pipeline offers no warning.
- E2019:00Trusted releaseRelease system
Provenance record lacks the compile-input attestation
The release record links commit → job → signature, but no attestation binds the compile inputs actually present on the worker. That gap is the failed trust boundary.
- E2422:30Downstream signalEndpoint telemetry
Marker string observed in the released artifact inventory
Artifact inventory scanning reports the inert marker ATTACK_LAB_MARKER_NS_482 inside the signed release. In the real world this is the moment the theory becomes a finding.
- E2925:00InvestigationRelease system
Provenance gap documented as the failed boundary
Case note records the conclusion: the failed trust boundary is the build environment, between checkout and compile. Signature and repository integrity remained intact throughout.
PATH 03
T1591
Reviewed ATT&CK technique
Instructional lead · Exact ATT&CK technique overlap
Documented public behavior · MITRE ATT&CK
The active MITRE ATT&CK Enterprise release maps FIN7 to T1591 Gather Victim Org Information. Consult the official group record for its cited procedure examples.
Historical source context · not replay attribution
Synthetic replay mapping · E02 to E02
Northstar fixture observations below unlock only when the replay reaches them. They do not assert this group performed the simulated activity.
- E0201:00ReconnaissanceEgress proxy
Reconnaissance — reasoning about the environment, no intrusion
The emulated adversary reads the vendor's public technology inventory. No intrusion step is modelled or described.