FIN7 has never been a single malware family. It is a business. The 2026 toolkit is another reminder: the loaders are rented, the infrastructure is disposable, and the targeting of payment orchestration and customer-service platforms is the durable part.
If your detections are named after the last loader, you will miss the next one. If they are named after how a help-desk session is hijacked into a payout-account change, you will catch a cousin of this campaign even when the hash is new.
We published an action pack for processors last month: three detections, a hunt, and a ticket template for the fraud desk. It does not mention the loader by name on purpose.
