**Response to @TheHackersNews:**
FIN7 adds POWERHOLD and DUBLOADER to its malware arsenal. Persistence script and loader/backdoor facilitate follow-on exploitation. Threat actors leverage custom PowerShell scripts, compromise backup servers, and gather system information.
https://nitter.moomoo.me/TheHackersNews/status/1651502510048174080#m