ATT&CKReferencesMandiant FIN5 GrrCON Oct 2016

Mandiant FIN5 GrrCON Oct 2016

Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareRawPOS

RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data.

T1018
Remote System Discovery
GroupFIN5

FIN5 has used the open source tool Essential NetTools to map the network and build a list of targets.

T1036.004
Masquerade Task or Service
MalwareRawPOS

New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager".

T1059
Command and Scripting Interpreter
GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1070.004
File Deletion
GroupFIN5

FIN5 uses SDelete to clean up the environment and attempt to prevent detection.

T1074.001
Local Data Staging
GroupFIN5

FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment.

T1078
Valid Accounts
GroupFIN5

FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment.

T1090.002
External Proxy
GroupFIN5

FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel.

T1110
Brute Force
GroupFIN5

FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials.

T1119
Automated Collection
GroupFIN5

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.

T1133
External Remote Services
GroupFIN5

FIN5 has used legitimate VPN, Citrix, or VNC credentials to maintain access to a victim environment.

T1543.003
Windows Service
MalwareRawPOS

RawPOS installs itself as a service to maintain persistence.

T1560.003
Archive via Custom Method
MalwareRawPOS

RawPOS encodes credit card data it collected from the victim with XOR.

T1572
Protocol Tunneling
MalwareFLIPSIDE

FLIPSIDE uses RDP to tunnel traffic from a victim environment.

T1588.002
Tool
GroupFIN5

FIN5 has obtained and used a customized version of PsExec, as well as use other tools such as pwdump, SDelete, and Windows Credential Editor.

T1685.005
Clear Windows Event Logs
GroupFIN5

FIN5 has cleared event logs from victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.