Alpha Cyber

Tracking FIN7: Hidden Infrastructure Behind Global Intrusions

Threat Hunt Intelligence FIN7 Infrastructure Hunt, 26 Attributed Hosts C2 Panel · Malware · Loader · 26 attributed · 48 ambient commodity · 74 surfaced Hunt #45Scope C2 Panel · Malware · LoaderAttributed 26Ambient 48Generated 2026-07-07 19:08 UTC This report…

Alpha Cyber Research7 min readupdated 7 Jul 2026
  • Exposing the Invisible
FIN7 Infrastructure Breakdown

C2 Panel · Malware · Loader · 26 attributed · 48 ambient commodity · 74 surfaced

Hunt

#45

Scope

C2 Panel · Malware · Loader

Attributed

26

Ambient

48

Generated

2026-07-07 19:08 UTC

HIGH THREAT LEVEL

26 hosts attributed to FIN7 (feed-corroborated), high-impact categories present (C2 Panel / Ransomware / RAT). 48 ambient commodity hosts shown for context only.

Threat context. Command-and-control panels are the operator-facing management interfaces adversaries use to issue tasking, collect output, and coordinate implants across victim networks. Exposed panels visible to internet-wide scanners reveal live infrastructure still reachable, giving defenders a rare chance for pre-exploitation blocking and pivoting. Disrupting C2 infrastructure degrades the operator’s ability to move laterally, exfiltrate data, or deploy additional payloads.

Threat Actor Profile & Attribution

Motivation

Financial

Active since

~2013

MITRE ATT&CK G0046 ↗

(public reporting)

Notable operations

(landmark public campaigns, context, not this hunt’s findings)

Carbanak bank-network thefts (estimated $1B+ across financial institutions).

Point-of-sale malware campaigns against US hospitality & retail.

Pivot to ransomware affiliate operations (DarkSide / BlackMatter, ALPHV/BlackCat, Black Basta).

2024–2025: sold the AuKill / AvNeutralizer EDR-killer on marketplaces; deployed the Python Anubis backdoor via compromised SharePoint; pushed NetSupport RAT through malicious MSIX packages.

Tooling we can hunt

(documented tools with an internet-scan signature)


Cobalt Strike

PowerShell Empire / Starkiller

JSSLoader

Metasploit

Coverage gaps

(custom implants with no external scan signature, cannot be hunted from internet-wide scans)


Carbanak

Anubis

Diceloader

POWERTRASH

Families swept

, Cobalt Strike, Empire / Starkiller, Metasploit, Loader panels

(shared/commodity tooling, attribution scored below)

Attribution method. Commodity tooling (Cobalt Strike, Sliver, Metasploit) is shared across many actors and red teams. Only feed-corroborated or actor-unique-family hosts are treated as attributed; family-signature-only hosts are shown as ambient context, scored “Possible,” not confirmed FIN7.

Live hunt hosts

by attribution tier (74 total)

Confirmed (attributed)

26 (35%)

Probable

0 (0%)

Possible (ambient)

48 (65%)

The 48 “Possible” hosts are

ambient context

, commodity C2 matching this family’s scan signature, shown for breadth and

not

attributed to FIN7.

Highest-confidence hosts

(the attributed set)

HostAttributionWhy
95.111.10.148ConfirmedA feed identifies JSSLoader, a malware family unique to FIN7. Exclusive-family identification is strong attribution.
193.203.48.23ConfirmedFeed-attributed FIN7 malware host.
78.253.144.46ConfirmedC2IntelFeeds attributes this C2 server to FIN7.
52.11.125.44ConfirmedFeed-attributed FIN7 malware host.
80.84.49.50ConfirmedFeed-attributed FIN7 malware host.
188.138.98.105ConfirmedFeed-attributed FIN7 malware host.

Data hygiene: 1 non-routable address (192.168.0.100, RFC 1918 private) was filtered from the confirmed set as a feed artefact. It cannot be live adversary infrastructure.

Threat-intel corroboration, feed corpus

(53 known-FIN7 indicators across 5 feeds: AlienVault OTX, C2IntelFeeds, MISP OSINT, ThreatFox, sslbl)

The actor’s known infrastructure mined from our synced feed corpus. The reference set that underpins the 26 attributed hosts above.

Infrastructure in corpus:

Malware host ×28 · Ransomware panel ×8 · Network host ×7 · C2 server ×3 · Phishing host ×3 · Loader panel ×2 · TLS cert ×1 · RAT controller ×1

Feed-corpus IOCs

by tier

Confirmed

52 (98%)

Probable

1 (2%)

Possible

0 (0%)
IndicatorInfra typeSourceTierLinked via
18e337e72ef9ade65b792b500df754918e1188afC2 TLS cert (SHA-1)sslblProbableFIN7
71.34.228.84C2 server (IP)AlienVault OTXConfirmedFIN7
128.48.139.176Loader panel (IP)C2IntelFeedsConfirmedFIN7
78.253.144.46C2 server (IP)C2IntelFeedsConfirmedFIN7
aaa.stage.14919005.www1.proslr3.comPhishing hostAlienVault OTXConfirmedFIN7
stage.14919005.www1.proslr3.comPhishing hostAlienVault OTXConfirmedFIN7

Key Metrics

74

Hosts Surfaced

26

Attributed (FIN7)

48

Ambient (commodity)

26

Feed-corroborated

53%

Avg Detection Conf.

53

Feed-corpus IOCs

Threat Category Distribution

74

C2 Panel

50

(68%)

Malware

19

(26%)

Loader

2

(3%)

RAT

1

(1%)

Ransomware

1

(1%)

Phishing

1

(1%)

MITRE ATT&CK, FIN7 Documented TTPs

FIN7’s documented techniques from public reporting (MITRE G0046). This is an infrastructure hunt (C2 panels, not host telemetry), so these are the actor’s known TTPs to hunt internally, not behaviours observed on the hosts above.

TacticTechniqueIDRelevance
Initial AccessPhishingT1566Spearphishing attachments/links; 2024–25 malvertising and fake-software lures (NetSupport RAT via MSIX).
ExecutionCommand & Scripting: PowerShellT1059.001POWERTRASH loader and Empire tradecraft.
ExecutionUser Execution: Malicious FileT1204.002Victims run weaponised documents / fake installers.
Defense EvasionImpair Defenses: Disable/Modify ToolsT1562.001AuKill / AvNeutralizer EDR-killer (sold on criminal marketplaces).
Command & ControlApplication Layer ProtocolT1071Cobalt Strike / Empire / Anubis backdoor C2 (Anubis uses Base64 over HTTP).
Resource DevelopmentAcquire InfrastructureT1583Rents VPS/cloud C2 and loader panels. The surface this hunt targets.
ImpactData Encrypted for ImpactT1486Ransomware affiliate operations (DarkSide/BlackMatter, ALPHV, Black Basta).

Top Geographies

Based on the 48 ambient hosts with scan enrichment (geo / port / hosting). Percentages are of 48.

Commodity family-sweep hosts, internet infrastructure matching FIN7’s tooling signature. Shown for context; not confirmed as FIN7’s own infrastructure. (Note: the CN/HK concentration does not match FIN7’s US/EU victimology, a further sign these are commodity, not actor-operated.)

China (CN)

26 (54%)

United States (US)

18 (38%)

Hong Kong (HK)

3 (6%)

Singapore (SG)

1 (2%)

Global Threat Geography

The 48 ambient (commodity) hosts, mapped. Shown for context; not confirmed FIN7 infrastructure.

31826SGHKUSCN

Bubble area ∝ host count · exact per-country counts in Top Geographies

48 hosts · 4 countries

Infrastructure Graph

ASN AS398823JARM 2ad2ad16d2ad2ad0…ASN AS36352colocrossing.comASN AS2914JARM 2ad2ad16d2ad2ad2…jQueryASN AS132203Alphabet Inc

ASN

Cert

Domain

IP

JARM

16 nodes · 17 links

Top Hosting Organisations

The 48 ambient hosts with scan enrichment. Organisations normalised (Alibaba/Aliyun and Tencent case-variants merged); percentages are of 48. Shown for context; not confirmed FIN7 infrastructure.

Alibaba / Aliyun Cloud

12 (25%)

Tencent Cloud (Beijing)

9 (19%)

JD / Beijing Jingdong 360

4 (8%)

NTT America, Inc.

4 (8%)

RackNerd LLC

3 (6%)

PEG TECH INC

2 (4%)

Exposed Ports & Services

The 48 ambient hosts with scan enrichment. Percentages are of 48. Shown for context; not confirmed FIN7 infrastructure.

50050 · Cobalt Strike

31 (65%)

443 · HTTPS

8 (17%)

80 · HTTP

2 (4%)

8444 · C2-alt

1 (2%)

18443 · C2-alt

1 (2%)

8848 · C2-alt

1 (2%)

8443 · HTTPS-alt

1 (2%)

8446 · C2-alt

1 (2%)

Port 50050 (Cobalt Strike team-server default) on two-thirds of enriched hosts confirms this ambient set is a commodity Cobalt Strike sweep, a slice of which will be legitimate red-team, research, or honeypot systems.

Confidence Distribution

High (≥70%)

39 (53%)

Medium (40–70%)

0 (0%)

Low (<40%)

35 (47%)

Detection confidence across all 74 hosts (how sure the sweep is that the host runs the tool). Separate from attribution: the 26 attributed hosts are feed-corroborated regardless of detection score.

Indicators of Compromise (top 24 attributed of 26 · feed-corroborated)

IPCategoryThreatSourceConf.Tier
95.111.10.148LoaderFIN7 (JSSLoader)Feed90%Confirmed
193.203.48.23MalwareFIN7Feed90%Confirmed
52.11.125.44MalwareFIN7Feed90%Confirmed
80.84.49.50MalwareFIN7Feed90%Confirmed
188.138.98.105MalwareFIN7Feed90%Confirmed
37.1.212.100MalwareFIN7Feed90%Confirmed
185.174.172.241MalwareFIN7Feed90%Confirmed
94.156.133.69MalwareFIN7Feed90%Confirmed
213.227.155.8MalwareFIN7Feed90%Confirmed
185.180.196.35MalwareFIN7Feed90%Confirmed
104.193.252.151MalwareFIN7Feed90%Confirmed
23.253.126.58MalwareFIN7Feed90%Confirmed
107.181.155.151MalwareFIN7Feed90%Confirmed
85.25.84.223MalwareFIN7Feed90%Confirmed
194.146.180.40MalwareFIN7Feed90%Confirmed
109.230.199.227RATFIN7Feed90%Confirmed
45.67.229.148RansomwareFIN7Feed90%Confirmed
31.148.219.141MalwareFIN7Feed90%Confirmed
204.155.31.174MalwareFIN7Feed90%Confirmed
204.155.31.167MalwareFIN7Feed90%Confirmed
198.100.119.7MalwareFIN7Feed90%Confirmed
198.100.119.6PhishingFIN7Feed90%Confirmed
78.253.144.46C2 PanelFIN7Feed90%Confirmed
128.48.139.176LoaderFIN7Feed90%Confirmed

Feed-attributed FIN7 hosts (no scan-side port/geo, hence omitted). 1 private/bogon address (192.168.0.100) was filtered as a feed artefact. The 48 ambient commodity hosts are available in the full SIEM/SOAR export, tagged as unconfirmed.

AI / ML Analysis

High

AI Threat Level

70

/100

Composite Risk

2

Anomalies

10

Infra Clusters

Infrastructure clusters by type (10 total):

JARM

3 (30%)

Infrastructure

3 (30%)

Subnet

2 (20%)

SSL/TLS

2 (20%)

AI composite risk

70/100 · HIGH

AI assessment. 26 hosts are confirmed adversary infrastructure attributed to a tracked actor (FIN7) via feeds, treat as an active threat. The 48 ambient hosts raise the surface but are not attributed.

2 subnet cluster(s), likely co-located infrastructure.

3 JARM cluster(s), shared C2-framework fingerprints (validate before attributing; commodity JARMs co-cluster unrelated operators).

Primary category: C2 Panel (50 hosts).

Top anomalies by score:

Anomalous hostPortAnomaly score
45.202.249.88500500.46
8.163.49.50500500.46

Block and monitor the 26 attributed FIN7 IPs at the perimeter firewall, NDR sensor, and EDR policy first. Run a retrospective query across DNS, proxy, and flow logs for connections to these hosts over the past 90 days. Rotate credentials and API tokens reachable from any segment that touched flagged infrastructure.

Treat the 48 ambient commodity hosts as leads, not confirmed FIN7, validate before hard-blocking, since a Cobalt Strike sweep includes legitimate red-team and research systems.

Pivot on shared network attributes, ASN, JARM fingerprint, TLS issuer, certificate subject, to uncover adjacent infrastructure, discarding hubs that resolve to commodity/scanner signatures.

Hunt internally for the FIN7 MITRE ATT&CK techniques mapped above (T1566, T1059.001, T1562.001, T1071, T1486): run retrospective queries across EDR, SIEM, and proxy logs to determine whether any tactic has already succeeded.

Export the complete IOC set to your SIEM/SOAR for automated alerting, and schedule a recurring hunt to detect infrastructure drift, adversaries rotate IPs and redeploy to evade static blocklists.

Alpha Cyber

, Exposing the Invisible · alpha-cyber.com

+972-53-945-9977 · Strategic Threat Intelligence

CONFIDENTIAL, Prepared by Alpha Cyber for the named recipient. Intelligence reflects data available at generation time and is provided for authorised defensive use only. Attribution is evidence-graded (confirmed / probable / possible), not a guarantee, infrastructure can be shared, rented, or spoofed; corroborate before acting.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]