FIN5

G0053

Threat group.View on attack.mitre.org

About this group

FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian.

Techniques used11

Procedure examples11

TechniqueProcedure example
T1018
Remote System Discovery

FIN5 has used the open source tool Essential NetTools to map the network and build a list of targets.

T1059
Command and Scripting Interpreter

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1070.004
File Deletion

FIN5 uses SDelete to clean up the environment and attempt to prevent detection.

T1074.001
Local Data Staging

FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment.

T1078
Valid Accounts

FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment.

T1090.002
External Proxy

FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel.

T1110
Brute Force

FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials.

T1119
Automated Collection

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1133
External Remote Services

FIN5 has used legitimate VPN, Citrix, or VNC credentials to maintain access to a victim environment.

T1588.002
Tool

FIN5 has obtained and used a customized version of PsExec, as well as use other tools such as pwdump, SDelete, and Windows Credential Editor.

T1685.005
Clear Windows Event Logs

FIN5 has cleared event logs from victims.

Software6

Campaigns0

None recorded.

References3

  1. DarkReading FireEye FIN5 Oct 2015 Open source
    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.
  2. FireEye Respond Webinar July 2017 Open source
    Scavella, T. and Rifki, A. (2017, July 20). Are you Ready to Respond? (Webinar). Retrieved October 4, 2017.
  3. Mandiant FIN5 GrrCON Oct 2016 Open source
    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.