Harpy, also referred to as Griffon, is a JavaScript-based backdoor associated with FIN7, also tracked as CARBON SPIDER. It has been used in financially motivated intrusion activity and broader post-compromise operations conducted by the group. Harpy supports resilient command-and-control communications, including use of HTTP with DNS as a fallback channel when the primary method fails, reflecting FIN7’s emphasis on maintaining access in contested environments.
Harpy has been distributed through malicious Microsoft Office documents, including Word documents used in phishing campaigns. In observed 2021 activity, FIN7 used themed lure documents to deliver Harpy to Windows victims. After establishing contact with its command-and-control infrastructure, Harpy was observed receiving and executing a JavaScript system-enumeration module, indicating a role in host discovery and follow-on intrusion enablement.
The malware forms part of FIN7’s broader intrusion toolkit alongside loaders, post-exploitation frameworks, and credential-access tooling. FIN7 has historically targeted sectors such as retail, hospitality, and restaurants, while also expanding into other industries including finance, technology, energy, government, and telecommunications. Within those operations, Harpy functions as a backdoor for persistent remote access and post-exploitation activity on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
APT41 used the Steam community page as a fallback mechanism for C2. Bazar has the ability to use an alternative C2 server if the primary server fails. BISCUIT malware contains a secondary fallback command and control server that is contacted after the primary command and control server.
FIN7's Harpy backdoor malware can use DNS as a backup channel for C2 if HTTP fails. OilRig malware ISMAgent falls back to its DNS tunneling mechanism if it is unable to reach the C2 server over HTTP. QUADAGENT uses multiple protocols (HTTPS, HTTP, DNS) for its C2 server as fallback channels if communication with one is unsuccessful.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor delivered via malicious Word documents; after C2 contact it can receive and execute a JavaScript system-enumeration module resembling tooling from the Domenus suite.
Backdoor malware that uses DNS as a fallback C2 channel when HTTP communication fails.
Backdoor that can fail over from HTTP-based C2 to DNS-based C2 as a backup channel.
Backdoor that can fail over from HTTP C2 to DNS-based C2 as a backup communications channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.