ATT&CKReferencesFireEye FIN6 Apr 2019

FireEye FIN6 Apr 2019

McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFIN6

FIN6 has used Windows Credential Editor for credential dumping.

T1003.003
NTDS
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1016
System Network Configuration Discovery
ToolAdFind

AdFind can extract subnet information from Active Directory.

T1018
Remote System Discovery
ToolAdFind

AdFind has the ability to query Active Directory for computers.

T1021.001
Remote Desktop Protocol
GroupFIN6

FIN6 used RDP to move laterally in victim networks.

T1036.004
Masquerade Task or Service
GroupFIN6

FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service.

T1059
Command and Scripting Interpreter
GroupFIN6

FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files.

T1059.001
PowerShell
GroupFIN6

FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener.

T1059.003
Windows Command Shell
GroupFIN6

FIN6 has used kill.bat script to disable security tools.

T1069.002
Domain Groups
ToolAdFind

AdFind can enumerate domain groups.

T1078
Valid Accounts
GroupFIN6

To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes.

T1087.002
Domain Account
ToolAdFind

AdFind can enumerate domain users.

T1102
Web Service
GroupFIN6

FIN6 has used Pastebin and Google Storage to host content for their operations.

T1134
Access Token Manipulation
GroupFIN6

FIN6 has used has used Metasploit’s named-pipe impersonation technique to escalate privileges.

T1482
Domain Trust Discovery
ToolAdFind

AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory.

T1569.002
Service Execution
GroupFIN6

FIN6 has created Windows services to execute encoded PowerShell commands.

T1588.002
Tool
GroupFIN6

FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind.

T1685
Disable or Modify Tools
GroupFIN6

FIN6 has deployed a utility script named kill.bat to disable anti-virus.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.