New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update Attacks
Essential information
- Published
- 13/06/2025 20:55
- Modified
- 18/06/2025 13:00
- Tags
- 2025-06-13 7-zip fake updates fin7 infrastructure maskbat netsupport rat powernet tag-124
- Related entities
- 1 intrusion sets (apt), 10 techniques (mitre), 3 malware, 3 others
Description
Insikt Group uncovered new infrastructure linked to GrayAlpha, a threat actor associated with FIN7. They identified a custom PowerShell loader named PowerNet that deploys NetSupport RAT, and another loader called MaskBat. Three main infection vectors were discovered: fake browser updates, fake 7-Zip download sites, and the TAG-124 traffic distribution system. While all three methods were used simultaneously, only the fake 7-Zip sites remained active at the time of writing. The analysis also led to the identification of a potential individual involved in GrayAlpha operations. The group's sophisticated tactics highlight the need for comprehensive security measures, including application allow-listing, employee training, and advanced detection techniques.