Threat group.View on attack.mitre.org
FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
FIN6 has used Windows Credential Editor for credential dumping. |
| T1003.003 NTDS |
FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1005 Data from Local System |
FIN6 has collected and exfiltrated payment card data from compromised systems. |
| T1018 Remote System Discovery |
FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1021.001 Remote Desktop Protocol |
FIN6 used RDP to move laterally in victim networks. |
| T1027.010 Command Obfuscation |
FIN6 has used encoded PowerShell commands. |
| T1036.004 Masquerade Task or Service |
FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service. |
| T1046 Network Service Discovery |
FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1047 Windows Management Instrumentation |
FIN6 has used WMI to automate the remote execution of PowerShell scripts. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
FIN6 has sent stolen payment card data to remote servers via HTTP POSTs. |
| T1053.005 Scheduled Task |
FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS. |
| T1059 Command and Scripting Interpreter |
FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files. |
| T1059.001 PowerShell |
FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener. |
| T1059.003 Windows Command Shell |
FIN6 has used |
| T1059.007 JavaScript |
FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.