ATT&CKReferencesFireEye Hacking FIN4 Dec 2014

FireEye Hacking FIN4 Dec 2014

Vengerik, B. et al.. (2014, December 5). Hacking the Street? FIN4 Likely Playing the Market. Retrieved December 17, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1056.001
Keylogging
GroupFIN4

FIN4 has captured credentials via fake Outlook Web App (OWA) login pages and has also used a .NET based keylogger.

T1056.002
GUI Input Capture
GroupFIN4

FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials.

T1059.005
Visual Basic
GroupFIN4

FIN4 has used VBA macros to display a dialog box and collect victim credentials.

T1071.001
Web Protocols
GroupFIN4

FIN4 has used HTTP POST requests to transmit data.

T1078
Valid Accounts
GroupFIN4

FIN4 has used legitimate credentials to hijack email communications.

T1090.003
Multi-hop Proxy
GroupFIN4

FIN4 has used Tor to log in to victims' email accounts.

T1114.002
Remote Email Collection
GroupFIN4

FIN4 has accessed and hijacked online email communications using stolen credentials.

T1204.001
Malicious Link
GroupFIN4

FIN4 has lured victims to click malicious links delivered via spearphishing emails (often sent from compromised accounts).

T1204.002
Malicious File
GroupFIN4

FIN4 has lured victims to launch malicious attachments delivered via spearphishing emails (often sent from compromised accounts).

T1564.008
Email Hiding Rules
GroupFIN4

FIN4 has created rules in victims' Microsoft Outlook accounts to automatically delete emails containing words such as “hacked," "phish," and “malware" in a likely attempt to prevent organizations from communicating about their activities.

T1566.001
Spearphishing Attachment
GroupFIN4

FIN4 has used spearphishing emails containing attachments (which are often stolen, legitimate documents sent from compromised accounts) with embedded malicious macros.

T1566.002
Spearphishing Link
GroupFIN4

FIN4 has used spearphishing emails (often sent from compromised accounts) containing malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.