Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRawPOS | RawPOS dumps memory from specific processes on a victim system, parses the dumped files, and scrapes them for credit card data. |
| T1018 Remote System Discovery |
GroupFIN5 | FIN5 has used the open source tool Essential NetTools to map the network and build a list of targets. |
| T1036.004 Masquerade Task or Service |
MalwareRawPOS | New services created by RawPOS are made to appear like legitimate Windows services, with names such as "Windows Management Help Service", "Microsoft Support", and "Windows Advanced Task Manager". |
| T1059 Command and Scripting Interpreter |
GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| T1070.004 File Deletion |
GroupFIN5 | FIN5 uses SDelete to clean up the environment and attempt to prevent detection. |
| T1074.001 Local Data Staging |
GroupFIN5 | FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment. |
| T1078 Valid Accounts |
GroupFIN5 | FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment. |
| T1090.002 External Proxy |
GroupFIN5 | FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel. |
| T1110 Brute Force |
GroupFIN5 | FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials. |
| T1119 Automated Collection |
GroupFIN5 | FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results. |
| T1133 External Remote Services |
GroupFIN5 | FIN5 has used legitimate VPN, Citrix, or VNC credentials to maintain access to a victim environment. |
| T1543.003 Windows Service |
MalwareRawPOS | RawPOS installs itself as a service to maintain persistence. |
| T1560.003 Archive via Custom Method |
MalwareRawPOS | RawPOS encodes credit card data it collected from the victim with XOR. |
| T1572 Protocol Tunneling |
MalwareFLIPSIDE | FLIPSIDE uses RDP to tunnel traffic from a victim environment. |
| T1588.002 Tool |
GroupFIN5 | FIN5 has obtained and used a customized version of PsExec, as well as use other tools such as pwdump, SDelete, and Windows Credential Editor. |
| T1685.005 Clear Windows Event Logs |
GroupFIN5 | FIN5 has cleared event logs from victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.