Security firm FireEye has discovered that the hacking group is using a new tool, a malware loader, that drops payloads directly into the memory of a targeted machine. It also has a new feature (RAT) that links to legitimate remote administration software from ATM maker NCR Corporation.
Researchers have named the new memory-infecting malware dropper BOOSTWRITE. They found that it can load more than one payload. One of them is the Carbanak backdoor, which has been previously linked to the FIN7 group.
Hackers initially use BOOSTWRITE and then infect machines with the new RAT, called RDFSNIFFER.
BOOSTWRITE uses a hijacking technique to load its own malicious files into the infected system's memory. These allow the retrieval of the initialization vector (IV) and the decryption key, which are necessary to decrypt the embedded payloads.
“Once the key and IV are downloaded, the malware decrypts the embedded payloads and performs checks,” the researchers report. “The payloads are expected to be PE32.DLLs that are loaded into memory without tampering with the system .”
Researchers analyzed BOOSTWRITE and found that hackers were using the loader to install two payloads: the Carbanak backdoor and RDFSNIFFER.
Additionally, in one of the BOOSTWRITE samples analyzed, the researchers observed that a code signing certificate from MANGO ENTERPRISE LIMITED was being used.
“By exploiting code signing certificates, the FIN7 group increases the chances of bypassing various security and the chances of successfully attacking victims,”the company said.

In-memory RATs
The RDFSNIFFER function is delivered as a payload to targeted machines. As we mentioned above, it is a RAT. It allows remote access to the Aloha Command Center Client application of ATM manufacturer, NCR. Through it, hackers “can interact with victims through existing legitimate 2FA sessions.”
Whenever legitimate software is run on compromised machines, RDFSNIFFER affects the NCR Corporation RDFClient process.
In this way, hackers are able to monitor or even modify connections made through RDFClient, having in their hands a tool for carrying out a man-in-the-middle attack.
“RDFSNIFFER also contains a backdoor that allows an attacker to upload, download, execute and/or delete files.”.
The FIN7 hacking team is constantly evolving its methods
The group was discovered by researchers in mid-2015. It is also known by the names Carbanak and Cobalt. Its main targets are banks and POS machines, and it has also attacked various European and American companies via the Carbanak.
Last year, some members of the FIN7 group were arrested. However, its malicious activities continue. The hackers are using even more sophisticated tools, such as those now discovered by researchers at FireEye's Mandiant.
Arbor Networks, after the arrest of the group members, detected a phishing campaign targeting banks in Russia and Romania, originating from the FIN7 group.
In May, other attacks were discovered, which, according to researchers, used the same tactics and techniques as the FIN7 hackers.
“These attacks have exploited typical and well-known FIN7 tools, such as CARBANAK and BABYMETAL, however, the introduction of new tools and techniques provides further evidence that FIN7 continues to evolve in response to improved security practices,” the researchers say.
