Recent FIN7 activities have included the deployment of ransomware but much of the TTP’s have remained consistent enough to attribute the activities to FIN7.
Furthermore, the group was infiltrated by security researchers who gained access to Jabber chat logs that allowed them to analyze and identify the groups hierarchy, team structures as well as conflicts present within the teams and management as well as identify associations that FIN7 is actively involved with.