article · 2026-05-21 · Attack Nemesis Research

What FIN7’s latest toolkit means for payment processors

The loaders changed. The interest in card-present and orchestration platforms did not. A practical read for fraud and detection teams.

FIN7 has never been a single malware family. It is a business. The 2026 toolkit is another reminder: the loaders are rented, the infrastructure is disposable, and the targeting of payment orchestration and customer-service platforms is the durable part.

If your detections are named after the last loader, you will miss the next one. If they are named after how a help-desk session is hijacked into a payout-account change, you will catch a cousin of this campaign even when the hash is new.

We published an action pack for processors last month: three detections, a hunt, and a ticket template for the fraud desk. It does not mention the loader by name on purpose.

Questions

Common questions

What changed in FIN7’s 2026 toolkit?
The loaders are rented and the infrastructure is disposable; the targeting of payment orchestration and customer-service platforms is the durable part. Attack Nemesis Research treats FIN7 as a business, not a malware family.
How should payment processors detect FIN7?
Name detections after the behavior, such as a help-desk session hijacked into a payout-account change, not after the last loader. That catches a cousin of the campaign even when the hash is new. Attack Nemesis recommends detecting how FIN7 gets paid, not what it installs.
What is in the Attack Nemesis processor action pack?
Three detections, a hunt, and a ticket template for the fraud desk. It leaves out the loader name on purpose, so it stays useful after the loader changes. Attack Nemesis action packs are built to outlive the malware.
Who should read this note?
Fraud and detection teams at payment processors, especially where the fraud desk and the SOC still brief different campaigns. Attack Nemesis wrote this for the teams who have to stop the payout.

Next step

See the platform against your environment.

A forty-minute briefing: your sources, your stack, and the tickets that should already exist.