Morphisec reported that FIN7 launched two campaigns against restaurant and hospitality organizations using password-protected Microsoft Word documents with Russian-language lures and branding themed around Finjan’s InvinciBull VPN. Victims were prompted to enable macros, which extracted obfuscated JavaScript, copied and renamed wscript.exe to mses.exe to reduce some EDR visibility, and installed a JavaScript backdoor that contacted command-and-control domains including bing-cdn[.]com and googleapi-cdn[.]com. The malware transmitted limited host profiling data such as MAC address and computer domain, indicating the operators were likely filtering victims before delivering additional payloads.
The activity fits long-observed FIN7 tradecraft documented by Mandiant and Splunk, including lure documents tied to malware families such as CARBANAK, GRIFFON, BATELEUR, POWERSOURCE, and BEACON, as well as JavaScript-based loaders that use WMI, ActiveX, and HTTP or DNS for reconnaissance and command-and-control. The new campaign also underscores FIN7’s resilience after multiple U.S. prosecutions of senior members, including recruiter Andrii Kolpakov’s guilty plea and administrator Fedir Hladyr’s prison sentence, while prior reporting has linked the group to large-scale payment-card theft and later expansion into ransomware-related operations.

Get the infrastructure and lures behind it.
14 events from the most recent confirmed update back to the earliest known activity.
Morphisec reported two November FIN7 campaigns and said the group remained active despite prior indictments. The report described the lures, macro behavior, JavaScript backdoor, and selective host profiling sent to command-and-control infrastructure.
Mandiant published a dataset of malicious document filenames and MD5 hashes attributed to FIN7 and suspected FIN7 activity. The indicator list mapped lure files to malware families including BEACON, BELLHOP, HALFBAKED, CARBANAK, DRIFTPIN, POWERSOURCE, BATELEUR, and GRIFFON.
Splunk published analysis describing FIN7 tradecraft and the resurfacing of JSS Loader and Remcos in the field. The report detailed JavaScript execution chains, host reconnaissance, and data exfiltration methods associated with the group.
A U.S. federal judge sentenced Fedir Hladyr to 10 years in prison and ordered $2.5 million in restitution. Prosecutors described him as a key technical figure in FIN7's theft of payment card data and credentials from hundreds of U.S. firms.
Andrii Kolpakov pleaded guilty in the United States to conspiracy to commit wire and bank fraud and conspiracy to commit computer hacking. Prosecutors identified him as a FIN7 manager and recruiter involved in a scheme that caused more than $100 million in losses during his participation.
FIN7 conducted a campaign in early 2020 that used the U.S. Postal Service to send malicious USB devices to multiple organizations. The activity showed the group remained operational despite prior arrests.
Fedir Hladyr pleaded guilty to wire fraud and conspiracy to commit computer hacking for his role in FIN7. The plea was part of an agreement intended to reduce his sentence.
After his 2018 arrest in Spain, Andrii Kolpakov was extradited to the United States to face charges tied to FIN7's hacking and fraud scheme.
A FIN7 lure document named "Oprosnik_new.doc" was created, according to its metadata. Morphisec later tied it to a campaign targeting the restaurant and hospitality sector.
Spanish police arrested alleged FIN7 manager and recruiter Andrii Kolpakov. Authorities said devices seized from him contained thousands of payment card numbers and stolen credentials from American companies.
German authorities arrested alleged FIN7 administrator Fedir Hladyr. He was later extradited to the U.S. for prosecution.
In the second week of November, FIN7 used closely related lure documents, including "dinners.doc," with minor macro changes and a different known C2 domain, googleapi-cdn[.]com. Morphisec said the samples were submitted from Ukraine and appeared to have been created only days earlier.
In the first week of November, FIN7 ran a phishing campaign targeting the restaurant and hospitality sector using password-protected Word documents with Russian-language lures and spoofed Finjan InvinciBull branding. Enabling macros led to obfuscated JavaScript execution, renaming of wscript.exe to mses.exe, and deployment of a backdoor communicating with bing-cdn[.]com.
Three high-ranking alleged FIN7 members were indicted, according to Morphisec's account of later campaign activity. The indictment did not stop subsequent FIN7 operations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourcecloud.google.com
Open sourcesplunk.com
Open sourcecyberscoop.com
Open sourcecyberscoop.com
Open sourceprodaft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.