Stats
- First seen
- June 2024
- Last seen
- October 2026
Description
Detects document exploitation behavior associated with the FIN7 criminal group's malicious document campaigns. FIN7 maldocs typically run script through document shell objects to download payloads, so this signature marks likely hands-on intrusion staging.
No cross-references or related blog posts found for this signature.