216.73.217.98

New FIN7-Linked Infrastructure, PowerNet Loader, and Fake Update Attacks

· Published 13/06/2025 20:55 · Modified 18/06/2025 13:00

Export JSON

Essential information

Published
13/06/2025 20:55
Modified
18/06/2025 13:00
Tags
2025-06-13 7-zip fake updates fin7 infrastructure maskbat netsupport rat powernet tag-124
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 3 malware, 3 others

Description

Insikt Group uncovered new linked to GrayAlpha, a threat actor associated with . They identified a custom PowerShell loader named that deploys , and another loader called . Three main infection vectors were discovered: fake browser updates, fake download sites, and the traffic distribution system. While all three methods were used simultaneously, only the fake sites remained active at the time of writing. The analysis also led to the identification of a potential individual involved in GrayAlpha operations. The group's sophisticated tactics highlight the need for comprehensive security measures, including application allow-listing, employee training, and advanced detection techniques.

External references