GrayAlpha is a financially motivated cybercriminal threat cluster with significant overlap to FIN7 and is widely assessed as part of, or closely affiliated with, the broader FIN7 ecosystem. The cluster has been linked through shared infrastructure, tooling, and tradecraft, and has continued to rely on infrastructure associated with Stark Industries and PQ.Hosting-linked services into 2025. GrayAlpha is associated with malware delivery operations that use social-engineering lures and fake software distribution channels to infect victims. Observed infection vectors include fake browser update pages, counterfeit software download sites impersonating 7-Zip, and use of the TAG-124 traffic distribution system. These delivery chains have been used to deploy NetSupport RAT. GrayAlpha has also used custom loaders including PowerNet, a PowerShell-based loader that decompresses and executes NetSupport RAT, and MaskBat, an obfuscated loader with similarities to FakeBat. Additional reporting links GrayAlpha to fake browser update websites impersonating widely used business, media, and software brands, and to malicious browser-extension activity involving FireClient. The cluster’s tradecraft aligns with FIN7’s long-running pattern of financially motivated intrusion activity, including sophisticated malware development, social engineering, and evolving delivery mechanisms. FIN7 has historically targeted organizations worldwide, especially in retail, hospitality, and financial services, and is known for customized malware, payment-card theft, and unauthorized access to corporate networks. More recent FIN7-linked activity has included advanced loaders, endpoint security evasion tooling, and expansion into ransomware and ransomware-as-a-service operations. GrayAlpha appears to represent a contemporary operational cluster within that ecosystem focused on malware delivery and access operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GrayAlpha (FIN7) is a financially motivated threat group known for sophisticated malware campaigns, including fake browser extensions and malvertising to deliver backdoors like FireClient.
Threat cluster overlapping with FIN7; observed relying on Stark Industries infrastructure through mid-2025.
Financially motivated malware distribution and social engineering operations using fake browser/software update lures and TDS-based delivery; suspected use of custom PowerShell loaders (PowerNet, MaskBat) to deploy NetSupport RAT; focuses on information theft and network compromise.
Cybercrime group known for financially motivated attacks, recently observed with new infrastructure for ongoing operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.