#FIN7
[sighs] critical support to FIN7
Today I presented at Virus Bulletin's conference in Dublin about a new network of "AI Nudify" websites created by FIN7. The sites promise to turn a regular photo into a non-consensual nude photo --- but the only thing they deliver is malware....
December 8, 2024 at 9:51 PM
Today we are releasing a report on new infrastructure and tooling linked to GrayAlpha, a financially motivated threat actor overlapping with FIN7 🧵
www.recordedfuture.com/research/gra...
GrayAlpha Unmasked: New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update Attacks
Insikt Group exposes GrayAlpha’s evolving infrastructure and infection methods—including PowerNet and MaskBat loaders, fake 7-Zip sites, and the undocumented TAG-124 network—linking the group to FIN7’...
www.recordedfuture.com
June 13, 2025 at 2:35 PM
My presentation from @virusbtn.bsky.social on FIN7's network of "AI Nudify" websites that trick people into downloading malware is now live @ www.youtube.com/watch?v=sPDI...
December 8, 2024 at 6:39 PM
Today I presented at Virus Bulletin's conference in Dublin about a new network of "AI Nudify" websites created by FIN7. The sites promise to turn a regular photo into a non-consensual nude photo --- but the only thing they deliver is malware....
November 13, 2024 at 7:54 AM
Prodaft has published a technical analysis of Anubis, a new Python-based backdoor linked to Savage Ladybug (FIN7) operations

catalyst.prodaft.com/public/repor...
March 16, 2025 at 10:39 AM
Às vezes, as pessoas tem o que merecem, né? #bolhasec
AI 'Nude Photo Generator' Delivers Infostealers, Not Images
The FIN7 group is using sophisticated malware campaign that spans numerous websites, to lure people with a deepfake tool promising to create nudes out of photos.
www.darkreading.com
October 5, 2024 at 2:47 PM
oh no, people who wanted to use nudify apps got pwned instead

[cracks open a tiny violin like a Russian nesting doll to reveal an even tinier violin inside]

www.404media.co/a-network-of...
A Network of AI ‘Nudify’ Sites Are a Front for Notorious Russian Hackers
Fin7 has made multiple ‘nudify’ sites that promise to use AI to undress photos of people but which are actually vehicles for malware, according to researchers. 404 Media found one advertised on one of...
www.404media.co
October 4, 2024 at 4:46 PM
But this malware has also been found impersonating half a dozen other major brands -- and this is likely the start of even more FIN7 campaigns targeting end-users with specific fake websites. 👀🌩️⚖️
November 13, 2024 at 8:43 AM
🚨 New research reveals Ragnar Loader, a powerful malware used by cybercrime groups like FIN7 and Ragnar Locker.

With advanced encryption, PowerShell payloads, and stealth injection, it hides deep within networks for long-term access.
#MalwareAnalysis #CyberAlerts
thehackernews.com/2025/03/fin7...
FIN7, FIN8, and Others Use Ragnar Loader for Persistent Access and Ransomware Operations
Ragnar Loader malware enables ransomware groups to maintain stealthy access, evade detection, and execute remote control operations.
thehackernews.com
March 8, 2025 at 9:59 PM
New from 404 Media: a network of 'nudify' sites, that say they can use AI to undress images, are actually a front for a notorious group of Russian hackers. We found one of the sites advertised on the web's biggest porn aggregator; massive honeypot www.404media.co/a-network-of...
A Network of AI ‘Nudify’ Sites Are a Front for Notorious Russian Hackers
Fin7 has made multiple ‘nudify’ sites that promise to use AI to undress photos of people but which are actually vehicles for malware, according to researchers. 404 Media found one advertised on one of...
www.404media.co
October 2, 2024 at 1:02 PM
Detect malicious activity linked to the FIN7-affiliated GrayAlpha group, which employs diverse infection vectors to deploy PowerNet Loader, NetSupport RAT, and MaskBat Loader using a set of Sigma rules in the SOC Prime Platform.
socprime.com/blog/detect-...
#cybersecurity #detectionengineering
GrayAlpha Operation Detection: The Fin7-Affiliated Group Spreads PowerNet Loader, NetSupport RAT, and MaskBat Loader | SOC Prime
Detect GrayAlpha operation spreading PowerNet Loader, NetSupport RAT and MaskBat Loader with Sigma rules from SOC Prime Platform.
socprime.com
June 17, 2025 at 12:06 PM
Ransomware scum make it personal for Reg readers by impersonating tech support
Ransomware scum make it personal for Reg readers by impersonating tech support
That invitation to a Teams call on which IT promises to mop up a spamstorm may not be what it seems Two ransomware campaigns are abusing Microsoft Teams to infect organizations and steal data, and the crooks may have ties to Black Basta and FIN7,…
dlvr.it
January 22, 2025 at 9:34 AM
Today let's take a look at #Russia 's FIN7 threat group, one that focuses on financial sectors primarily. First detected in approximately late 2015, the group has evolved in it's attacks since and moved from spear phishing to more focus on ransomware. www.bleepingcomputer.com/news/securit...
Notorious FIN7 hackers sell EDR killer to other threat actors
The notorious FIN7 hacking group has been spotted selling its custom "AvNeutralizer" tool, used to evade detection by killing enterprise endpoint protection software on corporate networks.
www.bleepingcomputer.com
August 31, 2024 at 4:34 AM
Cybersecurity experts uncover new #FIN7 infrastructure in Russia and Estonia, revealing the threat actor's evolving network strategy and global reach.
thehackernews.com/2024/08/rese...
#cybersecurity #hacking #malware
Researchers Uncover New Infrastructure Tied to FIN7 Cybercrime Group
Cybersecurity experts uncover new FIN7 infrastructure in Russia and Estonia, revealing the threat actor's evolving network strategy and global reach.
thehackernews.com
August 19, 2024 at 9:54 PM
ICYMI: My team published a deep dive into GrayAlpha's operations. The group uses multiple infection methods to deliver PowerNet Loader and NetSupport RAT.

Solid work from the team on this one. Full report here:
www.recordedfuture.com/research/gra...
June 17, 2025 at 8:55 AM
A young relative (minor female) of mine has been victimized by AI-generated nudes. The family is having to push hard for prosecution—and the nudes are out there forever. I don’t condone malware but…miigwech FIN7 for doing good work.
Today I presented at Virus Bulletin's conference in Dublin about a new network of "AI Nudify" websites created by FIN7. The sites promise to turn a regular photo into a non-consensual nude photo --- but the only thing they deliver is malware....
December 8, 2024 at 9:55 PM
Russian cybercriminals impersonate tech support on Microsoft Teams, overwhelming targets with spam then using remote access to install malware and steal data. Sophos identifies Fin7 and Storm-1811 as perpetrators of this UK-focused attack. The UK government plans to ban ransomware payments.
January 25, 2025 at 1:38 AM