Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—FIN7 remains a ransomware-capable cybercrime group, and CYFIRMA’s Q2 2026 report assesses that its operational activity increased significantly from April through June 2026. The group is not new: it has a long record of financially motivated attacks, and its more recent tradecraft includes automated exploitation of public-facing applications and tools designed to tamper with endpoint security. Because the latest activity claim comes from CYFIRMA, treat it as that firm’s assessment rather than a confirmed account of every attack attributed to FIN7.

What FIN7 is—and what “returns” means

FIN7, tracked by MITRE as G0046, is a financially motivated cybercrime group also known as Carbon Spider, ELBRUS, and Sangria Tempest. “FIN7 ransomware” is shorthand for ransomware operations associated with the group; FIN7 itself is an actor, not a ransomware product.

MITRE records a shift toward big-game hunting from 2020, including use of REvil and FIN7’s own DarkSide ransomware-as-a-service activity. In this context, “returns” refers to renewed operational activity and evolving methods, not the formation of a new group. Attribution can vary in confidence: a campaign’s use of a tool associated with FIN7 does not, by itself, prove that FIN7 directly operated that campaign.

What newer FIN7 activity has been reported?

Activity reported for April–June 2026

CYFIRMA’s Q2 2026 APT report assesses that FIN7 significantly increased its operational activity during April–June 2026. It reports campaigns against financial institutions, government entities, logistics providers, technology companies, and industrial organizations across Asia, Europe, and North America. The report describes ransomware, financial malware, destructive-wiper capabilities, and VPN-focused intrusion techniques. These are CYFIRMA’s reported findings; they should not be read as independently confirmed incidents in every named sector or region.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Automation and security-tool tampering reported in 2024

SentinelLabs’ July 17, 2024 report, “FIN7 Reboot,” described automated attack methods and updated defense evasion. Its technical summary identifies automated SQL-injection attacks against public-facing applications and AvNeutralizer, also known as AuKill, a tool designed to tamper with endpoint-security products. A newer version used ProcLaunchMon.sys, a built-in Windows driver.

ENISA’s 2025 threat landscape says FIN7 was observed advertising AvNeutralizer/AuKill to multiple ransomware groups in July 2024. ENISA links the tool to campaigns involving AvosLocker, MedusaLocker, BlackCat/ALPHV, Trigona, and LockBit. This illustrates why the tool’s presence is evidence of a security threat, but not by itself proof that FIN7 conducted a particular ransomware attack.

Rank #2
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

How FIN7 can get in and impair EDR

Automated exploitation of exposed applications

SentinelLabs reported automated SQL-injection attacks against public-facing applications. SQL injection abuses an application’s handling of database queries; a vulnerable internet-facing service can therefore create an entry point without an attacker first gaining access through a user’s inbox. The report establishes this as a method in FIN7’s described tradecraft, not as the method used in every FIN7 intrusion.

AvNeutralizer/AuKill and endpoint defenses

Endpoint detection and response (EDR) tools monitor devices for suspicious activity and help security teams investigate or contain it. AvNeutralizer/AuKill is designed to interfere with security products, which can reduce visibility or disrupt protection if the attacker succeeds. SentinelLabs described a newer version using ProcLaunchMon.sys; the existence of a driver-based technique does not mean every EDR product is bypassed or that the method always works.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
  • World’s First 6TB 2.5” Portable Hard Drive
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption

ENISA’s account that the tool was advertised to multiple ransomware groups matters operationally: defenders should not assume that a detected AuKill-related component identifies FIN7 as the direct operator. Investigators need to assess the full intrusion evidence, including initial access, identity activity, persistence, lateral movement, and the ransomware or other payload.

Which organizations and regions are in scope?

CYFIRMA’s Q2 2026 assessment names financial institutions, government, logistics, technology, and industrial organizations, with reported activity across Asia, Europe, and North America. These are broad sectors and regions, not a guarantee that every organization in them is targeted or that organizations elsewhere are safe. CYFIRMA’s Q2 2026 assessment does not establish a specific company list, victim count, or FIN7-specific ransom total for this reporting period.

Rank #4
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
  • SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
  • Capture ATP with RTDMI for Enterprise: Defend against zero-day exploits and ransomware using multi-engine cloud sandboxing and advanced memory inspection.
  • Full Threat Protection Stack: Includes Gateway AV, Intrusion Prevention, Anti-Spyware, Application Control, and Content Filtering for layered defense.
  • 24x7 Global Support & Firmware Updates: Keep your firewall protected and operational with continuous technical assistance and critical firmware upgrades.
  • Application Intelligence & Network Control: Identify and control network activity with deep traffic analytics and reporting features.

How large FIN7’s documented historical impact is

The FBI’s 2018 case summary says that, in the United States, FIN7 breached companies’ computer networks in 47 states and the District of Columbia and stole more than 15 million customer card records from over 6,500 point-of-sale terminals at more than 3,600 business locations. These figures describe the FBI’s historical account of FIN7’s payment-card activity; they are not a measure of the group’s current ransomware victims.

For broader context only, FinCEN reported in 2025 that it received 7,395 Bank Secrecy Act reports concerning 4,194 ransomware incidents and more than $2.1 billion in ransomware payments during January 2022–December 2024. Those are sector-wide figures, not totals attributable to FIN7.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
  • Slim durable design to help take your important files with you
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What businesses should do to reduce risk

FIN7’s reported methods point to a combination of internet-facing exposure, identity security, endpoint resilience, and recovery readiness. No single control guarantees prevention, especially when an attacker may try to impair security tooling.

  • Patch and reduce exposure. Inventory internet-facing applications and VPN appliances, remediate known vulnerabilities promptly, remove unused services, and restrict administrative interfaces from public access where possible. Prioritize application testing for injection flaws.
  • Protect identities. Require multifactor authentication (MFA), particularly for remote access and administrator accounts. Use phishing-resistant MFA where it is available, limit standing privileges, and monitor unusual sign-ins and changes to authentication settings.
  • Harden and monitor endpoints. Keep endpoint protection enabled and updated, restrict who can install or load drivers, and alert on attempts to stop security services or tamper with EDR. Ensure alerts reach a monitored response team; a deployed agent alone is not an incident-response capability.
  • Prepare recoverable backups. Maintain offline or immutable backups for critical systems and test restoration regularly. Keep backup administration separate from ordinary user and server credentials so an intruder cannot easily alter both production systems and recovery copies.
  • Rehearse the response. Define who can isolate systems, contact incident responders, preserve logs, notify leadership, and restore operations. Include scenarios involving compromised VPN access, impaired endpoint security, data theft, and destructive malware.

What to do if you suspect a FIN7-related intrusion

  1. Activate your incident-response process. Contact your internal security lead or a qualified incident-response provider, and use established emergency channels rather than potentially compromised corporate accounts.
  2. Contain affected systems carefully. Isolate confirmed compromised devices and accounts from the network where feasible. Avoid wiping machines or making broad changes before responders preserve evidence; immediate safety and operational needs may require faster containment.
  3. Preserve evidence. Retain endpoint alerts, authentication and VPN logs, firewall records, application logs, suspicious files, and timestamps. Record which systems were isolated and what actions were taken.
  4. Investigate access and scope. Review internet-facing application and VPN activity, identity-provider events, privilege changes, security-tool tampering, and signs of lateral movement or data exfiltration. Do not rely on an AuKill-related indicator alone to attribute the incident to FIN7.
  5. Recover from known-good sources. Restore only after responders have addressed the initial access path and validated the recovery environment. Reset credentials and revoke sessions or tokens that may have been exposed, prioritizing privileged and remote-access accounts.

What the evidence does—and does not—establish

The FBI’s historical case summary and MITRE’s group profile establish FIN7’s long-running financially motivated activity and its move into ransomware operations. SentinelLabs and ENISA describe relevant 2024 tradecraft and the circulation of a security-tampering tool. CYFIRMA provides the cited assessment of increased activity in Q2 2026. Together, these sources support treating FIN7 as a current defensive concern, but they do not establish a complete list of recent victims, a definitive attribution for every campaign, or a FIN7-specific ransomware payment total.

Quick Recap

SaleBestseller No. 1
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$129.80
Bestseller No. 2
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
WD 4TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBPKJ0040BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$180.10
SaleBestseller No. 3
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
World’s First 6TB 2.5” Portable Hard Drive; Slim durable design to help take your important files with you
$259.00
Bestseller No. 4
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
SonicWall Advanced Protection Service Suite for NSA3700-3 Year License (02-SSC-6910) - Capture ATP, App Control, Threat Prevention & 24x7 Support
SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
$11,163.19
SaleBestseller No. 5
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$213.00

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.