FIN10

G0051

Threat group.View on attack.mitre.org

About this group

FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizations.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1021.001
Remote Desktop Protocol

FIN10 has used RDP to move laterally to systems in the victim environment.

T1033
System Owner/User Discovery

FIN10 has used Meterpreter to enumerate users on remote systems.

T1053.005
Scheduled Task

FIN10 has established persistence by using S4U tasks as well as the Scheduled Task option in PowerShell Empire.

T1059.001
PowerShell

FIN10 uses PowerShell for execution as well as PowerShell Empire to establish persistence.

T1059.003
Windows Command Shell

FIN10 has executed malicious .bat files containing PowerShell commands.

T1070.004
File Deletion

FIN10 has used batch scripts and scheduled tasks to delete critical system files.

T1078
Valid Accounts

FIN10 has used stolen credentials to connect remotely to victim networks using VPNs protected with only a single factor.

T1078.003
Local Accounts

FIN10 has moved laterally using the Local Administrator account.

T1547.001
Registry Run Keys / Startup Folder

FIN10 has established persistence by using the Registry option in PowerShell Empire to add a Run key.

T1570
Lateral Tool Transfer

FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally.

T1588.002
Tool

FIN10 has relied on publicly-available software to gain footholds and establish persistence in victim environments.

Software1

Campaigns0

None recorded.

References1

  1. FireEye FIN10 June 2017 Open source
    FireEye iSIGHT Intelligence. (2017, June 16). FIN10: Anatomy of a Cyber Extortion Operation. Retrieved November 17, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.