Tracking FIN7: Hidden Infrastructure Behind Global Intrusions
Threat Hunt Intelligence FIN7 Infrastructure Hunt, 26 Attributed Hosts C2 Panel · Malware · Loader · 26 attributed · 48 ambient commodity · 74 surfaced Hunt #45Scope C2 Panel · Malware · LoaderAttributed 26Ambient 48Generated 2026-07-07 19:08 UTC This report…
- Exposing the Invisible

C2 Panel · Malware · Loader · 26 attributed · 48 ambient commodity · 74 surfaced
Hunt#45
ScopeC2 Panel · Malware · Loader
Attributed26
Ambient48
Generated2026-07-07 19:08 UTC
HIGH THREAT LEVEL
26 hosts attributed to FIN7 (feed-corroborated), high-impact categories present (C2 Panel / Ransomware / RAT). 48 ambient commodity hosts shown for context only.
Threat context. Command-and-control panels are the operator-facing management interfaces adversaries use to issue tasking, collect output, and coordinate implants across victim networks. Exposed panels visible to internet-wide scanners reveal live infrastructure still reachable, giving defenders a rare chance for pre-exploitation blocking and pivoting. Disrupting C2 infrastructure degrades the operator’s ability to move laterally, exfiltrate data, or deploy additional payloads.
Threat Actor Profile & Attribution
MotivationFinancial
Active since~2013
MITRE ATT&CK G0046 ↗(public reporting)
Notable operations(landmark public campaigns, context, not this hunt’s findings)
▸
Carbanak bank-network thefts (estimated $1B+ across financial institutions).
▸
Point-of-sale malware campaigns against US hospitality & retail.
▸
Pivot to ransomware affiliate operations (DarkSide / BlackMatter, ALPHV/BlackCat, Black Basta).
▸
2024–2025: sold the AuKill / AvNeutralizer EDR-killer on marketplaces; deployed the Python Anubis backdoor via compromised SharePoint; pushed NetSupport RAT through malicious MSIX packages.
Tooling we can hunt(documented tools with an internet-scan signature)
Cobalt Strike
PowerShell Empire / Starkiller
JSSLoader
Metasploit
Coverage gaps(custom implants with no external scan signature, cannot be hunted from internet-wide scans)
Carbanak
Anubis
Diceloader
POWERTRASH
Families swept, Cobalt Strike, Empire / Starkiller, Metasploit, Loader panels
(shared/commodity tooling, attribution scored below)
Attribution method. Commodity tooling (Cobalt Strike, Sliver, Metasploit) is shared across many actors and red teams. Only feed-corroborated or actor-unique-family hosts are treated as attributed; family-signature-only hosts are shown as ambient context, scored “Possible,” not confirmed FIN7.
by attribution tier (74 total)
Confirmed (attributed)
26 (35%)Probable
0 (0%)Possible (ambient)
48 (65%)The 48 “Possible” hosts are
ambient context, commodity C2 matching this family’s scan signature, shown for breadth and
notattributed to FIN7.
Highest-confidence hosts(the attributed set)
| Host | Attribution | Why |
|---|---|---|
| 95.111.10.148 | Confirmed | A feed identifies JSSLoader, a malware family unique to FIN7. Exclusive-family identification is strong attribution. |
| 193.203.48.23 | Confirmed | Feed-attributed FIN7 malware host. |
| 78.253.144.46 | Confirmed | C2IntelFeeds attributes this C2 server to FIN7. |
| 52.11.125.44 | Confirmed | Feed-attributed FIN7 malware host. |
| 80.84.49.50 | Confirmed | Feed-attributed FIN7 malware host. |
| 188.138.98.105 | Confirmed | Feed-attributed FIN7 malware host. |
Data hygiene: 1 non-routable address (192.168.0.100, RFC 1918 private) was filtered from the confirmed set as a feed artefact. It cannot be live adversary infrastructure.
Threat-intel corroboration, feed corpus(53 known-FIN7 indicators across 5 feeds: AlienVault OTX, C2IntelFeeds, MISP OSINT, ThreatFox, sslbl)
The actor’s known infrastructure mined from our synced feed corpus. The reference set that underpins the 26 attributed hosts above.
Infrastructure in corpus:Malware host ×28 · Ransomware panel ×8 · Network host ×7 · C2 server ×3 · Phishing host ×3 · Loader panel ×2 · TLS cert ×1 · RAT controller ×1
Feed-corpus IOCsby tier
Confirmed
52 (98%)Probable
1 (2%)Possible
0 (0%)| Indicator | Infra type | Source | Tier | Linked via |
|---|---|---|---|---|
| 18e337e72ef9ade65b792b500df754918e1188af | C2 TLS cert (SHA-1) | sslbl | Probable | FIN7 |
| 71.34.228.84 | C2 server (IP) | AlienVault OTX | Confirmed | FIN7 |
| 128.48.139.176 | Loader panel (IP) | C2IntelFeeds | Confirmed | FIN7 |
| 78.253.144.46 | C2 server (IP) | C2IntelFeeds | Confirmed | FIN7 |
| aaa.stage.14919005.www1.proslr3.com | Phishing host | AlienVault OTX | Confirmed | FIN7 |
| stage.14919005.www1.proslr3.com | Phishing host | AlienVault OTX | Confirmed | FIN7 |
Key Metrics
74
Hosts Surfaced
26
Attributed (FIN7)
48
Ambient (commodity)
26
Feed-corroborated
53%
Avg Detection Conf.
53
Feed-corpus IOCs
Threat Category Distribution
C2 Panel
50
(68%)
Malware
19
(26%)
Loader
2
(3%)
RAT
1
(1%)
Ransomware
1
(1%)
Phishing
1
(1%)
MITRE ATT&CK, FIN7 Documented TTPs
FIN7’s documented techniques from public reporting (MITRE G0046). This is an infrastructure hunt (C2 panels, not host telemetry), so these are the actor’s known TTPs to hunt internally, not behaviours observed on the hosts above.
| Tactic | Technique | ID | Relevance |
|---|---|---|---|
| Initial Access | Phishing | T1566 | Spearphishing attachments/links; 2024–25 malvertising and fake-software lures (NetSupport RAT via MSIX). |
| Execution | Command & Scripting: PowerShell | T1059.001 | POWERTRASH loader and Empire tradecraft. |
| Execution | User Execution: Malicious File | T1204.002 | Victims run weaponised documents / fake installers. |
| Defense Evasion | Impair Defenses: Disable/Modify Tools | T1562.001 | AuKill / AvNeutralizer EDR-killer (sold on criminal marketplaces). |
| Command & Control | Application Layer Protocol | T1071 | Cobalt Strike / Empire / Anubis backdoor C2 (Anubis uses Base64 over HTTP). |
| Resource Development | Acquire Infrastructure | T1583 | Rents VPS/cloud C2 and loader panels. The surface this hunt targets. |
| Impact | Data Encrypted for Impact | T1486 | Ransomware affiliate operations (DarkSide/BlackMatter, ALPHV, Black Basta). |
Top Geographies
Based on the 48 ambient hosts with scan enrichment (geo / port / hosting). Percentages are of 48.
Commodity family-sweep hosts, internet infrastructure matching FIN7’s tooling signature. Shown for context; not confirmed as FIN7’s own infrastructure. (Note: the CN/HK concentration does not match FIN7’s US/EU victimology, a further sign these are commodity, not actor-operated.)
China (CN)
26 (54%)United States (US)
18 (38%)Hong Kong (HK)
3 (6%)Singapore (SG)
1 (2%)Global Threat Geography
The 48 ambient (commodity) hosts, mapped. Shown for context; not confirmed FIN7 infrastructure.
Bubble area ∝ host count · exact per-country counts in Top Geographies
48 hosts · 4 countries
Infrastructure Graph
ASN
Cert
Domain
IP
JARM
16 nodes · 17 links
Top Hosting Organisations
The 48 ambient hosts with scan enrichment. Organisations normalised (Alibaba/Aliyun and Tencent case-variants merged); percentages are of 48. Shown for context; not confirmed FIN7 infrastructure.
Alibaba / Aliyun Cloud
12 (25%)Tencent Cloud (Beijing)
9 (19%)JD / Beijing Jingdong 360
4 (8%)NTT America, Inc.
4 (8%)RackNerd LLC
3 (6%)PEG TECH INC
2 (4%)Exposed Ports & Services
The 48 ambient hosts with scan enrichment. Percentages are of 48. Shown for context; not confirmed FIN7 infrastructure.
50050 · Cobalt Strike
31 (65%)443 · HTTPS
8 (17%)80 · HTTP
2 (4%)8444 · C2-alt
1 (2%)18443 · C2-alt
1 (2%)8848 · C2-alt
1 (2%)8443 · HTTPS-alt
1 (2%)8446 · C2-alt
1 (2%)Port 50050 (Cobalt Strike team-server default) on two-thirds of enriched hosts confirms this ambient set is a commodity Cobalt Strike sweep, a slice of which will be legitimate red-team, research, or honeypot systems.
Confidence Distribution
High (≥70%)
39 (53%)Medium (40–70%)
0 (0%)Low (<40%)
35 (47%)Detection confidence across all 74 hosts (how sure the sweep is that the host runs the tool). Separate from attribution: the 26 attributed hosts are feed-corroborated regardless of detection score.
Indicators of Compromise (top 24 attributed of 26 · feed-corroborated)
| IP | Category | Threat | Source | Conf. | Tier |
|---|---|---|---|---|---|
| 95.111.10.148 | Loader | FIN7 (JSSLoader) | Feed | 90% | Confirmed |
| 193.203.48.23 | Malware | FIN7 | Feed | 90% | Confirmed |
| 52.11.125.44 | Malware | FIN7 | Feed | 90% | Confirmed |
| 80.84.49.50 | Malware | FIN7 | Feed | 90% | Confirmed |
| 188.138.98.105 | Malware | FIN7 | Feed | 90% | Confirmed |
| 37.1.212.100 | Malware | FIN7 | Feed | 90% | Confirmed |
| 185.174.172.241 | Malware | FIN7 | Feed | 90% | Confirmed |
| 94.156.133.69 | Malware | FIN7 | Feed | 90% | Confirmed |
| 213.227.155.8 | Malware | FIN7 | Feed | 90% | Confirmed |
| 185.180.196.35 | Malware | FIN7 | Feed | 90% | Confirmed |
| 104.193.252.151 | Malware | FIN7 | Feed | 90% | Confirmed |
| 23.253.126.58 | Malware | FIN7 | Feed | 90% | Confirmed |
| 107.181.155.151 | Malware | FIN7 | Feed | 90% | Confirmed |
| 85.25.84.223 | Malware | FIN7 | Feed | 90% | Confirmed |
| 194.146.180.40 | Malware | FIN7 | Feed | 90% | Confirmed |
| 109.230.199.227 | RAT | FIN7 | Feed | 90% | Confirmed |
| 45.67.229.148 | Ransomware | FIN7 | Feed | 90% | Confirmed |
| 31.148.219.141 | Malware | FIN7 | Feed | 90% | Confirmed |
| 204.155.31.174 | Malware | FIN7 | Feed | 90% | Confirmed |
| 204.155.31.167 | Malware | FIN7 | Feed | 90% | Confirmed |
| 198.100.119.7 | Malware | FIN7 | Feed | 90% | Confirmed |
| 198.100.119.6 | Phishing | FIN7 | Feed | 90% | Confirmed |
| 78.253.144.46 | C2 Panel | FIN7 | Feed | 90% | Confirmed |
| 128.48.139.176 | Loader | FIN7 | Feed | 90% | Confirmed |
Feed-attributed FIN7 hosts (no scan-side port/geo, hence omitted). 1 private/bogon address (192.168.0.100) was filtered as a feed artefact. The 48 ambient commodity hosts are available in the full SIEM/SOAR export, tagged as unconfirmed.
AI / ML Analysis
High
AI Threat Level
70
/100
Composite Risk
2
Anomalies
10
Infra Clusters
Infrastructure clusters by type (10 total):
JARM
3 (30%)Infrastructure
3 (30%)Subnet
2 (20%)SSL/TLS
2 (20%)AI composite risk
70/100 · HIGH
AI assessment. 26 hosts are confirmed adversary infrastructure attributed to a tracked actor (FIN7) via feeds, treat as an active threat. The 48 ambient hosts raise the surface but are not attributed.
▸
2 subnet cluster(s), likely co-located infrastructure.
▸
3 JARM cluster(s), shared C2-framework fingerprints (validate before attributing; commodity JARMs co-cluster unrelated operators).
▸
Primary category: C2 Panel (50 hosts).
Top anomalies by score:
| Anomalous host | Port | Anomaly score |
|---|---|---|
| 45.202.249.88 | 50050 | 0.46 |
| 8.163.49.50 | 50050 | 0.46 |
Recommended Actions
▸
Block and monitor the 26 attributed FIN7 IPs at the perimeter firewall, NDR sensor, and EDR policy first. Run a retrospective query across DNS, proxy, and flow logs for connections to these hosts over the past 90 days. Rotate credentials and API tokens reachable from any segment that touched flagged infrastructure.
▸
Treat the 48 ambient commodity hosts as leads, not confirmed FIN7, validate before hard-blocking, since a Cobalt Strike sweep includes legitimate red-team and research systems.
▸
Pivot on shared network attributes, ASN, JARM fingerprint, TLS issuer, certificate subject, to uncover adjacent infrastructure, discarding hubs that resolve to commodity/scanner signatures.
▸
Hunt internally for the FIN7 MITRE ATT&CK techniques mapped above (T1566, T1059.001, T1562.001, T1071, T1486): run retrospective queries across EDR, SIEM, and proxy logs to determine whether any tactic has already succeeded.
▸
Export the complete IOC set to your SIEM/SOAR for automated alerting, and schedule a recurring hunt to detect infrastructure drift, adversaries rotate IPs and redeploy to evade static blocklists.
Alpha Cyber, Exposing the Invisible · alpha-cyber.com
+972-53-945-9977 · Strategic Threat Intelligence
CONFIDENTIAL, Prepared by Alpha Cyber for the named recipient. Intelligence reflects data available at generation time and is provided for authorised defensive use only. Attribution is evidence-graded (confirmed / probable / possible), not a guarantee, infrastructure can be shared, rented, or spoofed; corroborate before acting.



