FIN6

G0037

Threat group.View on attack.mitre.org

About this group

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.

Techniques used40

Procedure examples40

TechniqueProcedure example
T1003.001
LSASS Memory

FIN6 has used Windows Credential Editor for credential dumping.

T1003.003
NTDS

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1005
Data from Local System

FIN6 has collected and exfiltrated payment card data from compromised systems.

T1018
Remote System Discovery

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1021.001
Remote Desktop Protocol

FIN6 used RDP to move laterally in victim networks.

T1027.010
Command Obfuscation

FIN6 has used encoded PowerShell commands.

T1036.004
Masquerade Task or Service

FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service.

T1046
Network Service Discovery

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1047
Windows Management Instrumentation

FIN6 has used WMI to automate the remote execution of PowerShell scripts.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

FIN6 has sent stolen payment card data to remote servers via HTTP POSTs.

T1053.005
Scheduled Task

FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS.

T1059
Command and Scripting Interpreter

FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files.

T1059.001
PowerShell

FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener.

T1059.003
Windows Command Shell

FIN6 has used kill.bat script to disable security tools.

T1059.007
JavaScript

FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites.

View all 40 procedure examples

Software12

Campaigns0

None recorded.

References2

  1. FireEye FIN6 Apr 2019 Open source
    McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.
  2. FireEye FIN6 April 2016 Open source
    FireEye Threat Intelligence. (2016, April). Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.