May 2023, the U.S. attorney for Washington state declared “Fin7 is an entity no more,”
Fin7’s revival came in April 2024, when Blackberry wrote about an intrusion at a large automotive firm that began with malware served by a typosquatting attack targeting people searching for a popular free network scanning tool.
https://blogs.blackberry.com/en/2024/04/fin7-targets-the-united-states-automotive-industry
CNN, Costco, Dropbox, Grammarly, Google, Goto.com, Harvard, Lexis Nexis, Meta, Microsoft 365, Midjourney, Netflix, Paycor, Quickbooks, Quicken, Reuters, Regions Bank Onepass, RuPay, SAP (Ariba), Trezor, Twitter/X, Wall Street Journal, Westlaw, and Zoom, among others
According to Silent Push, the software currently being targeted by Fin7 includes 7-zip, PuTTY, ProtectedPDFViewer, AIMP, Notepad++, Advanced IP Scanner, AnyDesk, pgAdmin, AutoDesk, Bitwarden, Rest Proxy, Python, Sublime Text, and Node.js.
Malwarebytes blogged about a similar campaign in April
https://www.threatdown.com/blog/corporate-users-targeted-via-malicious-ads-and-modals/
FIN7 rents a large amount of dedicated IP on Stark Industries - analysts have discovered numerous Stark Industries IPs that are solely dedicated to hosting FIN7 infrastructure
typosquatting attacks, Fin7 registers domains that are similar to those for popular free software tools. Those look-alike domains are then advertised on Google so that sponsored links to them show up prominently in search results, which is usually above the legitimate source of the software in question
malicious site spoofing FreeCAD showing as sponsored by google