Mandiant published new reporting on FIN7, detailing how the financially motivated threat group has continued to operate as an elusive and adaptive global criminal enterprise. The report describes FIN7 as a long-running actor known for intrusion activity tied to cybercrime, with investigators emphasizing the group’s persistence, operational flexibility, and ability to evade disruption while maintaining a broad international footprint.
The findings highlight renewed efforts to identify and track the people, infrastructure, and tradecraft behind FIN7 as defenders and law enforcement continue pursuing the group. Mandiant’s account frames FIN7 as an enduring threat to organizations worldwide, underscoring the value of sustained threat intelligence collection and coordinated action against one of the most established names in financially driven intrusion activity.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Mandiant released a blog post detailing its pursuit and analysis of FIN7, describing the group as an enigmatic and evasive global criminal operation. The reference does not provide earlier dated events, so the publication itself is the only distinct event extractable from the content provided.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.