Threat group.View on attack.mitre.org
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE). |
| T1016.001 Internet Connection Discovery |
FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers. |
| T1018 Remote System Discovery |
FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used |
| T1021.001 Remote Desktop Protocol |
FIN8 has used RDP for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement. |
| T1027.010 Command Obfuscation |
FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads. |
| T1033 System Owner/User Discovery |
FIN8 has executed the command `quser` to display the session details of a compromised machine. |
| T1047 Windows Management Instrumentation |
FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
FIN8 has used FTP to exfiltrate collected data. |
| T1053.005 Scheduled Task |
FIN8 has used scheduled tasks to maintain RDP backdoors. |
| T1055.004 Asynchronous Procedure Call |
FIN8 has injected malicious code into a new svchost.exe process. |
| T1059.001 PowerShell |
FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access. |
| T1059.003 Windows Command Shell |
FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`. |
| T1068 Exploitation for Privilege Escalation |
FIN8 has exploited the CVE-2016-0167 local vulnerability. |
| T1070.004 File Deletion |
FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.