SOCFRAME / THRONE Journal
All reports

Scenario 03 · E-crime · Financially-motivated intrusion

Living off the land.
Seen anyway.

FIN7 — Carbon Spider — barely brings its own tools. The point-of-sale-and-ransomware affiliate crew drives its payloads through binaries Windows already trusts, so the malicious step reads as routine administration. We ran their signature living-off-the-land chain by hand on a Windows victim and finished with an in-memory credential dump. THRONE told the trusted binary from the adversary behaviour every time — and caught the dump on the way out.

Adversary
FIN7 · Carbon Spider
Attribution
e-crime · G0046
Signature
LOLBin proxy execution
Result
Detected end to end
Executive summary

Living off the land, caught anyway

FIN7 — tracked by CrowdStrike as Carbon Spider and by MITRE as G0046 — is one of the most prolific financially-motivated crews on record. Its defining habit is proxy execution: running code through signed, built-in Windows binaries so a payload never surfaces as a strange new process. This report walks the full run end to end.

On a single Windows host we executed FIN7's hallmark living-off-the-land chain — an mshta JavaScript loader, a regsvr32 "squiblydoo" scriptlet, a Windows Script Host dropper, and a WMI-spawned child process — and then performed the move that makes this crew dangerous rather than merely noisy: a credential dump of lsass.exe using the signed comsvcs.dll as a living-off-the-land MiniDump tool. None of it carried a novel binary. All of it was observable.

The headline result: seven distinct detections from one run, spanning execution, defense evasion, persistence and credential access — every LOLBin flagged on its own, and the LSASS dump caught as a separate, higher-severity signal. The telemetry, the alert IDs, the ATT&CK mappings and the triage below are reproduced as captured in the lab.

7
Alerts, one run
6
Windows binaries abused
6
ATT&CK techniques
1
LSASS dump caught
The adversary

Who FIN7 / Carbon Spider is

FIN7 is an e-crime group, not a nation-state actor — money is the motive, and the tradecraft is tuned for scale, stealth and repeatability rather than for a single high-value target.

Active since at least 2015, FIN7 built its reputation on large-scale payment-card theft. The group ran long phishing campaigns against retail, restaurant and hospitality chains — primarily in the United States — dropping malware onto point-of-sale environments and scraping cardholder data at volume. Early operations leaned on the CARBANAK backdoor and a family of custom loaders and implants, most famously the JavaScript implant GRIFFON, delivered inside weaponised Office documents and shortcut files. To staff operations the group stood up a fake offensive-security company, "Combi Security," that recruited penetration testers who did not always know who they were really working for.

FIN7's operators have faced real-world consequences — the U.S. Department of Justice has indicted and, in multiple cases, secured guilty pleas from members of the group — yet the operation adapted and continued. Over the last several years security researchers have tracked Carbon Spider's pivot from card theft into big-game ransomware, including links to ransomware-as-a-service operations such as DarkSide, BlackMatter and ALPHV/BlackCat, and to further recruitment fronts dressed up as legitimate security firms. The group that once scraped magnetic-stripe data now also deploys enterprise-wide encryption and extortion.

Signature tradecraft

What makes FIN7 worth emulating is not any one tool — it is a consistent preference for the land it is living off. The MITRE ATT&CK profile for G0046 and years of public reporting describe a group that reaches for signed Windows binaries again and again: mshta.exe to run HTA/JavaScript (T1218.005), regsvr32.exe to execute remote scriptlets (T1218.010), rundll32.exe as a proxy (T1218.011), the Windows Script Host for VBScript and JScript droppers (T1059.005 / T1059.007), WMI for stealthy process creation (T1047), PowerShell for in-memory stages (T1059.001), and scheduled tasks and application shimming for persistence (T1053.005, T1546.011). The through-line is trusted-binary proxy execution: borrow something Windows already signs and allows, and the malicious action hides inside expected behaviour. The subset we ran below is a faithful, non-destructive slice of exactly that style.

Setup & methodology

A hand-run subset, then a credential dump

The honest framing matters: this was a direct-execution run, not an autonomous command-and-control operation. We drove FIN7's techniques by hand and watched what THRONE made of them.

Every step ran on one Windows victim — WIN-J50RP1JBGD4 (204.168.192.149 · internal 10.0.0.5) — as a curated, non-destructive subset of the FIN7 playbook. We kept the recognisable loaders and the LSASS dump attempt and left out anything that would harm the host; there was no ransomware, no data theft, no destruction. We cleaned up afterward. This is a controlled technique test against real detection logic, not a live intrusion — and nothing in the lab is hidden: the hostname, both IP addresses, and every alert ID are shown as captured.

The host streams Sysmon telemetry to the THRONE cloud tenant. From the moment a process starts on the box to the moment a scored, investigable detection exists, the path is automatic and runs in seconds:

Direct execution on WIN-J50RP1JBGD4 → Sysmon event
→ tenant-tagged syslog → THRONE ingest :1514 → Kafka → ch_pump parse → ClickHouse
→ Sigma sweep (3,148 rules / 389 ATT&CK techniques) + behavioral engine → alert
→ ONYX auto-triage → incident → causality tree (parent/child process GUIDs)

Each stage earns its place. Sysmon provides the high-fidelity process, command-line and image-load events Windows' own logging often omits. Tenant-tagged syslog keeps the stream attributable as it crosses into the cloud. Kafka decouples ingest from parsing so a burst never drops events; ch_pump normalises each record and lands it in ClickHouse, where the Sigma sweep runs 3,148 rules mapped across 389 ATT&CK techniques alongside a behavioral engine that scores relationships rather than single lines. Whatever fires is handed to ONYX — THRONE's AI SOC analyst — which triages the raw alerts, correlates them into one investigation, and rebuilds the causality tree. No analyst is in the loop until there is something worth looking at.

The kill chain

Four trusted binaries, one credential dump

Every step below rode a binary that ships with Windows. THRONE flagged each one distinctly, then caught the credential-access move that followed. Here is the chain by ATT&CK tactic — what each command does, and why FIN7 reaches for it.

Detected
Defense evasionmshta JS loader · T1218.005
Detected
Defense evasionregsvr32 squiblydoo · T1218.010
Detected
ExecutionWScript VBS dropper · T1059.005
Detected
ExecutionWMI process spawn · T1047
Detected
Persistenceschtasks task · T1053.005
Detected
Credential accesscomsvcs LSASS MiniDump · T1003.001

Execution via mshta — JavaScript loader T1218.005

mshta.exe is the Microsoft HTML Application host. It will execute HTA files and inline javascript: or vbscript: directly from the command line, pulling script from a local path or a remote URL. Because mshta is a signed Microsoft binary, the code it runs inherits its trust and never appears as a new, unknown executable on disk. This is precisely how FIN7 has historically staged its GRIFFON JavaScript implant — the loader is the operating system's own tool, and the payload lives in script. In ATT&CK this is System Binary Proxy Execution: Mshta.

Defense evasion via regsvr32 "squiblydoo" T1218.010

"Squiblydoo" is the pattern regsvr32 /s /n /u /i:<url> scrobj.dll: regsvr32.exe is told to register a COM scriptlet, and the scrobj.dll script engine fetches and executes a remote .sct file — with no DLL ever written to disk and, on many configurations, no application-control block. It is a near-canonical allow-list bypass, which is exactly why a financially-motivated crew that wants to run everywhere, quietly, keeps it in the kit. The remote .sct scriptlet is itself a distinct, flaggable artefact.

Execution via the Windows Script Host T1059.005

The dropper stage runs a VBScript (or JScript) file through wscript.exe / cscript.exe, the Windows Script Host. Script droppers are cheap, easy to obfuscate, and look like the kind of automation that is genuinely common on managed Windows estates — so they rarely stand out on their own. FIN7 has leaned on Script Host droppers to unpack and launch later stages without compiling a single binary.

Execution via WMI T1047

Windows Management Instrumentation can create processes locally or against a remote host. When a child process is spawned by WmiPrvSE.exe — the WMI provider host — or launched via wmic process call create, the parent is a core management service rather than a shell, which both hides the lineage and opens a path to lateral movement. For a crew that spreads across an estate, WMI is a quiet way to execute that admins themselves use every day.

Persistence via Scheduled Task T1053.005

schtasks.exe /create registers a task that re-launches a payload on a trigger — logon, a time, an event. Scheduled tasks are a long-standing FIN7 persistence mechanism because they survive reboots, run with predictable privilege, and are indistinguishable at a glance from the hundreds of legitimate tasks already on a Windows box.

Credential access via comsvcs.dll MiniDump T1003.001

This is the pivot. rundll32.exe C:\Windows\System32\comsvcs.dll, MiniDump <lsass_pid> dump.bin full abuses the signed comsvcs.dll's MiniDump export to write the full memory of lsass.exe to disk — no Mimikatz, no ProcDump, nothing the operator had to bring. From that dump an attacker recovers credentials and ticket material, and a payment-card crew turned ransomware affiliate uses those credentials to move laterally and reach the servers worth encrypting. It is LSASS Memory credential dumping done entirely with built-in tools, which is why THRONE scores it above the execution noise.

The detections

What THRONE caught

Within seconds of each binary running, Sigma and the behavioral engine fired and ONYX — THRONE's AI SOC analyst — triaged the alerts. The full wave from this one run on WIN-J50RP1JBGD4:

AlertDetectionSevATT&CK
ALR-175444Suspicious JavaScript Execution Via Mshta.EXEHIGHT1218.005
ALR-175441LSASS Dump Keyword In CommandLineHIGHT1003.001
ALR-175446Scripting/CommandLine Process Spawned Regsvr32MEDT1218.010
ALR-175445Dropper Script Execution Via WScript/CScriptMEDT1059.005
ALR-175447/40WmiPrvSE / Wmic Spawned A ProcessMEDT1047
ALR-175443Execution of Suspicious File Type Extension (.sct)MEDT1218.010
ALR-175442Scheduled Task Creation Via Schtasks.EXELOWT1053.005

Seven alerts, one run. Read down the severity column and the shape of the intrusion appears on its own: a cluster of execution and defense-evasion signals at MED, a persistence signal held at LOW, and two HIGH alerts that mark the moments that matter — the mshta loader at the top of the chain and the LSASS dump at the end of it. The detail behind the most important rows is below.

ALR-175441 · LSASS Dump Keyword In CommandLine T1003.001

The most consequential detection in the run. This Sigma rule keys on command lines that carry the signature of an LSASS memory dump — the MiniDump export, the comsvcs.dll image, and a process argument resolving to lsass — regardless of which binary issues them. Because it watches the behaviour (dumping LSASS) and not a named tool, it fires on the living-off-the-land rundll32 comsvcs.dll path just as it would on Mimikatz. It maps to ATT&CK Credential Access, OS Credential Dumping: LSASS Memory, and ONYX scored it HIGH — a credential-access event arriving after an execution chain is the step most likely to precede lateral movement, so it anchors the incident.

ALR-175444 · Suspicious JavaScript Execution Via Mshta.EXE T1218.005

This rule keys on mshta.exe invoked with inline script — a javascript: / vbscript: handler or a scriptlet reference on the command line — rather than opening a benign local HTA. That command-line shape is the tell that mshta is being used as a code loader, which is the FIN7/GRIFFON pattern. Mapped to System Binary Proxy Execution: Mshta, it was raised HIGH as the opening move of the chain and became, in ONYX's reconstruction, the root that the later steps descend from.

ALR-175446 + ALR-175443 · regsvr32 squiblydoo T1218.010

The squiblydoo pattern produced two correlated signals. The first keys on a scripting or command-line parent spawning regsvr32.exe with the remote-scriptlet switches (/i: with a URL, scrobj.dll); the second keys independently on execution of the suspicious .sct scriptlet file type. Two rules describing one technique from different angles is a feature, not a duplication — it raises confidence that this is squiblydoo and not a stray regsvr32 call. Both map to System Binary Proxy Execution: Regsvr32 and were triaged MED, then folded into the same incident.

ALR-175447/40 · WmiPrvSE / Wmic Spawned A Process T1047

This detection keys on process-creation lineage: a child whose parent is WmiPrvSE.exe (or that was created by wmic process call create). It is a relationship rule — the command itself may be unremarkable, but the parentage is the signal. Mapped to Windows Management Instrumentation, it was scored MED; on its own WMI execution is common on managed estates, but in the company of an mshta loader and an LSASS dump, ONYX read it as part of the same hostile sequence rather than as background administration.

Why this is hard to catch

Trusted-binary proxy execution is designed to blend in — mshta, regsvr32, wscript and wmic are all legitimate parts of Windows, signed by Microsoft and present on every host. THRONE separates the legitimate binary from the adversary behaviour riding it: it keys on command-line shape, process lineage and image loads, not on a binary name or a hash. That is what lets it catch the comsvcs.dll LSASS MiniDump even though no malware was ever written to disk.

Evidence

How the chain reassembles itself

Individual alerts are only half the story. THRONE rebuilds causality from Sysmon's process identifiers — every process event carries a ProcessGuid and its ParentProcessGuid, so parent-to-child links can be reconstructed exactly rather than guessed from timestamps.

In this run those links are what turn seven separate alerts into one picture. The mshta loader (ALR-175444) sits at the root; the regsvr32 squiblydoo call (ALR-175446 / ALR-175443) and the Windows Script Host dropper (ALR-175445) descend from the execution stage; the WMI spawn (ALR-175447/40) shows a child hanging off WmiPrvSE.exe rather than a shell; and the credential dump (ALR-175441) appears as rundll32.exe reaching into lsass.exe. Reading the tree, an analyst sees not six unrelated LOLBin events but a single sequence that moves from a trusted-binary loader to a credential dump.

Causality from GUIDs, not guesswork

Because the tree is built from ProcessGuid / ParentProcessGuid rather than from wall-clock proximity, it holds up even when unrelated activity is interleaved on a busy host — the parentage is recorded by Sysmon at the moment each process starts, and ONYX walks those edges to assemble the incident.

Findings

Why it matters

The defensive lesson of a FIN7 run is uncomfortable: the adversary brought almost no tooling of its own and still lit up a full kill chain. The things that would catch a conventional attacker — a new binary, a bad hash, an unsigned executable — were never present.

That is what makes this crew hard. Every binary in the chain is signed by Microsoft and expected on the host, so allow-listing by name or trusting a signature catches nothing. The malicious content lives in script and in command-line arguments, not in files an antivirus engine will recognise, so the IOC surface is minimal. And the operation is deliberately shaped to look like administration: WMI process creation, scheduled tasks and script hosts are all things real admins do all day. A detection strategy built on "is this binary known-bad?" sees a quiet, legitimate Windows host right up until the credentials are gone.

The run also shows why the credential-access step is the one to anchor on. Execution and defense-evasion signals are where living-off-the-land is noisiest and most ambiguous; the LSASS dump is where intent becomes unmistakable. Catching the dump — and tying it back through the causality tree to the loader that started the chain — is the difference between seven low-context alerts and one explained incident.

Defensive takeaways

What to do about it

Four concrete moves, each drawn directly from how this chain behaved.

1 · Detect on behaviour and lineage, not on the binary

Signed binaries defeat name- and hash-based controls, so the signal has to come from command-line shape and parent/child relationships. Alert when mshta, regsvr32 or wscript run with remote-script or inline-script arguments, when they are spawned by Office or a shell, or when WmiPrvSE.exe is the parent of a new process. That is the layer FIN7 cannot hide in.

2 · Treat any LSASS access as a first-class event

Watch for the dump behaviour itself — MiniDump, comsvcs.dll, and processes opening handles to lsass.exe — independent of the tool used. A rule keyed on the behaviour catches the living-off-the-land rundll32 comsvcs path and Mimikatz alike, and it should page, not queue.

3 · Harden and constrain the LOLBins you can

Where the estate allows it, use application control (WDAC/AppLocker) and attack-surface-reduction rules to block or constrain mshta, regsvr32 remote scriptlets and Windows Script Host execution, and restrict outbound egress from these binaries so squiblydoo cannot fetch a remote .sct. You will not remove every path, but you shrink the land there is to live off.

4 · Centralise Sysmon and correlate to ATT&CK

A low-IOC, living-off-the-land chain only becomes visible when individual events are mapped to technique and then correlated into a sequence. Ship high-fidelity Sysmon telemetry to a platform that scores by ATT&CK technique and rebuilds causality — so the credential-access step is automatically linked to the loader that started it, and an analyst inherits an explained incident rather than a pile of alerts.