# FIN7

> As of 2026-05-30, FIN7 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning vulnerability, apt. Also known as ATK32, CARBON SPIDER, Calcium, Carbanak. ATT&CK coverage spans 33 techniques across 11 tactics in 2 of 2 tracked threats. Most-observed techniques: T1018 (Remote System Discovery), T1213 (Data from Information Repositories), T1003 (OS Credential Dumping).

- **Nation:** Russia
- **Tracked threats:** 2
- **Categories:** VULNERABILITY, APT
- **Also known as:** ATK32, CARBON SPIDER, Calcium, Carbanak, Coreid, ELBRUS, G0008, G0046, GOLD NIAGARA, ITG14, JokerStash, Sangria Tempest
- **As of:** 2026-05-30

## ATT&CK techniques observed

33 techniques observed across 2 of 2 tracked threats. Tactics: Discovery (8), Credential Access (6), Execution (3), Impact (3), Lateral Movement (3), Stealth (formerly Defense Evasion) (3).

- [T1018](https://intel.threadlinqs.com/technique/T1018) Remote System Discovery — Discovery — observed in 2 of 2 tracked threats
- [T1213](https://intel.threadlinqs.com/technique/T1213) Data from Information Repositories — Collection — observed in 2 of 2 tracked threats
- [T1003](https://intel.threadlinqs.com/technique/T1003) OS Credential Dumping — Credential Access — observed in 1 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1021](https://intel.threadlinqs.com/technique/T1021) Remote Services — Lateral Movement — observed in 1 of 2 tracked threats
- [T1021.002](https://intel.threadlinqs.com/technique/T1021.002) SMB/Windows Admin Shares — Lateral Movement — observed in 1 of 2 tracked threats
- [T1033](https://intel.threadlinqs.com/technique/T1033) System Owner/User Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1036.003](https://intel.threadlinqs.com/technique/T1036.003) Rename Legitimate Utilities — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 1 of 2 tracked threats
- [T1059.003](https://intel.threadlinqs.com/technique/T1059.003) Windows Command Shell — Execution — observed in 1 of 2 tracked threats
- [T1068](https://intel.threadlinqs.com/technique/T1068) Exploitation for Privilege Escalation — Privilege Escalation — observed in 1 of 2 tracked threats
- [T1069.002](https://intel.threadlinqs.com/technique/T1069.002) Domain Groups — Discovery — observed in 1 of 2 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 1 of 2 tracked threats

## Tracked threats

- [Veeam Backup & Replication 8 Critical Vulnerabilities — Domain User to Backup Server RCE (CVE-2026-21666, CVE-2026-21667, CVE-2026-21669, CVE-2026-21708)](https://intel.threadlinqs.com/threat/TL-2026-0232) — CRITICAL
- [CSVDE.exe LOLBIN for Active Directory Reconnaissance — FIN7 + APT10/menuPass Documented Usage, Bulk LDAP Export, Kerberoasting Precursor](https://intel.threadlinqs.com/threat/TL-2026-0113) — HIGH

## Related CVEs

8 CVEs referenced by tracked FIN7 activity.

- [CVE-2026-21708](https://intel.threadlinqs.com/cve/CVE-2026-21708)
- [CVE-2026-21672](https://intel.threadlinqs.com/cve/CVE-2026-21672)
- [CVE-2026-21671](https://intel.threadlinqs.com/cve/CVE-2026-21671)
- [CVE-2026-21670](https://intel.threadlinqs.com/cve/CVE-2026-21670)
- [CVE-2026-21669](https://intel.threadlinqs.com/cve/CVE-2026-21669)
- [CVE-2026-21668](https://intel.threadlinqs.com/cve/CVE-2026-21668)
- [CVE-2026-21667](https://intel.threadlinqs.com/cve/CVE-2026-21667)
- [CVE-2026-21666](https://intel.threadlinqs.com/cve/CVE-2026-21666)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/FIN7
