ATT&CKReferencesDarkReading FireEye FIN5 Oct 2015

DarkReading FireEye FIN5 Oct 2015

Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1078
Valid Accounts
GroupFIN5

FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment.

T1110
Brute Force
GroupFIN5

FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials.

T1133
External Remote Services
GroupFIN5

FIN5 has used legitimate VPN, Citrix, or VNC credentials to maintain access to a victim environment.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.