Skip to content
Flash Briefing high FinanceLegal & Professional

FIN7 Pivots to Financial Services with New Phishing Infrastructure and Loader Malware

The 2023 arrests disrupted FIN7’s operations. Evidently not permanently. New phishing infrastructure observed in April and May 2026 confirms the group has rebuilt its operational capability and is running active campaigns against mid-tier European financial institutions: wealth managers, independent brokers, payment processors, and trade finance firms.

FIN7 has operated since at least 2015. It has survived multiple law enforcement actions, member arrests, and infrastructure seizures. This resumption is consistent with the group’s history of reconstitution.

New Loader, Same Entry Point

FIN7’s core technique hasn’t changed: carefully constructed spear-phishing emails impersonating regulators, auditors, and trade associations. What’s changed is the follow-on capability. The new loader component, labelled “SideDoor” in threat intelligence reporting, establishes persistence and communicates with C2 infrastructure via HTTPS traffic that blends with normal business network activity. Standard perimeter filtering misses it.

Delivery is via malicious Word documents in emails posing as regulatory filings or compliance documentation. The lure content is contextually specific: FCA reporting deadlines, DORA compliance requirements, Basel IV calculations. Not generic phishing. The group invests in making these convincing, and mid-market firms with compliance teams handling exactly this type of correspondence are the intended audience.

Once the loader is active, FIN7 operators don’t act immediately. They conduct manual reconnaissance over days or weeks, mapping the environment before deploying further tooling. By the time anything triggers an alert, they’ve often had extended undetected access.

Why Mid-Market Firms Are the Target

The major retail banks aren’t the focus here. Their detection capability is generally sufficient to catch this class of attack before it progresses. FIN7 is targeting the organisations that have real money or monetisable data but haven’t made the security investment of a Tier 1 institution:

  • Wealth management firms with UHNW client data and significant AUM, where both the data and the assets have value
  • Brokers and market makers with direct connectivity to trading infrastructure
  • Payment processors sitting within the payment chain without full Tier 1 security controls
  • Trade finance and commodities firms with access to large, fast-moving transaction flows

The selection logic is straightforward: access to funds or data that can be monetised quickly, at targets where getting in and moving laterally doesn’t require defeating Tier 1 detection.

Immediate Actions for Financial Sector Security Teams

Four things that should be checked now, not at the next security review cycle:

Email filtering rules should flag macro-enabled Office file attachments from external senders; this is a basic control that stops a significant percentage of FIN7’s delivery mechanism before it reaches an inbox.

Phishing awareness training for client-facing and compliance staff needs to include examples that reflect current lures specifically. Generic training doesn’t prepare people for emails referencing the DORA deadline their firm is actively working toward.

EDR tuning should flag anomalous outbound HTTPS connections originating from Office application processes. The SideDoor loader uses this pattern to blend with normal traffic; it’s detectable if the alerting is configured for it.

MFA on all privileged accounts with access to banking systems. Credential theft is the objective once the loader is active, and MFA is the most effective single control against what FIN7 does after initial access.

The FCA is aware and a Dear CEO letter to mid-tier firms is anticipated in the coming weeks. Don’t wait for the letter.