GRIFFON is a JavaScript/JScript-based backdoor and downloader for Windows associated with the financially motivated FIN7 threat group, also tracked as ELBRUS and TA3546. It supports modular functionality for host reconnaissance, screen capture, persistence, and deployment of additional malware. Its reconnaissance module can retrieve the compromised system’s date and time, while its screenshot module captures the remote desktop. GRIFFON has used PowerShell to execute TinyMet, a Meterpreter downloader. Persistence mechanisms include Windows scheduled tasks and a module that stores the implant in the Windows Registry and executes it at user logon.
GRIFFON has been deployed through spear-phishing campaigns involving malicious documents and was used as a FIN7 payload by May 2018. It has also been observed as a follow-on payload loaded by JSSLoader, including in a campaign attributed to TA543. Its use is associated with financially motivated intrusions into organizations, particularly in the financial, retail, and hospitality sectors. GRIFFON provides a foothold and supports follow-on activity; payment-card theft, credential theft, and ransomware deployment performed elsewhere in FIN7 operations are not established as intrinsic GRIFFON capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ELBRUS is responsible for developing and distributing multiple custom malware families used for persistence, including JSSLoader and Griffon.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Spear phishing a target with a document loaded with a malware payload which as of May 2018 has been the Griffon payload.
During our analysis of JSSLoader, it additionally loaded a Griffon payload which is historically associated with another actor, TA3546, also known as FIN7 or Carbanak.
During our analysis of JSSLoader, it additionally loaded a Griffon payload which is historically associated with another actor, TA3546, also known as FIN7 or Carbanak.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The injected BadUSB command launched "powershell.exe -w hidden -ep bypass" and used Invoke-Expression to execute a downloaded stage in memory.
As soon as OSTAP is created in the form of a BAT file, this file is executed
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
33 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A FIN7 custom JavaScript-based downloader used as a subsequent payload stage following PowerShell-based BadUSB execution.
JavaScript malware/obfuscation component referenced as part of the payload chain and noted for its recognizable obfuscation pattern.
Backdoor/RAT referenced as part of FIN7’s toolset used after initial access to maintain control of compromised environments.
Custom backdoor/persistence malware used by ELBRUS/FIN7 in intrusions that can culminate in ransomware/extortion operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.