FIN7 Linked to Spear-Phishing Campaign Targeting U.S. Automotive Industry


The infamous cybercrime syndicate has been linked to a spear-phishing campaign targeting the . The group has been known for its sophisticated TTPs, which include social engineering techniques such as spear-phishing, to deliver to its victims.


The spear-phishing campaign discovered by the BlackBerry research and intelligence team is a classic example of how operates. The group identified employees at the targeted company who worked in the IT department and had higher administrative rights. The attackers then used social engineering techniques to trick the employees into clicking on a malicious link or downloading a file that contained the Carbanak (also known as Anunak).

Once the was installed on the targeted system, gained complete control over the system and could steal sensitive data, including financial information and . The group has been known to sell stolen data on the dark web for profit.

's latest attack on the highlights the growing threat of cybercrime in the digital age. Organizations must remain vigilant against attacks and implement robust security measures to protect their systems and data from cybercriminals.

