ATT&CKReferencesFireEye FIN10 June 2017

FireEye FIN10 June 2017

FireEye iSIGHT Intelligence. (2017, June 16). FIN10: Anatomy of a Cyber Extortion Operation. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupFIN10

FIN10 has used RDP to move laterally to systems in the victim environment.

T1033
System Owner/User Discovery
GroupFIN10

FIN10 has used Meterpreter to enumerate users on remote systems.

T1053.005
Scheduled Task
GroupFIN10

FIN10 has established persistence by using S4U tasks as well as the Scheduled Task option in PowerShell Empire.

T1059.001
PowerShell
GroupFIN10

FIN10 uses PowerShell for execution as well as PowerShell Empire to establish persistence.

T1059.003
Windows Command Shell
GroupFIN10

FIN10 has executed malicious .bat files containing PowerShell commands.

T1070.004
File Deletion
GroupFIN10

FIN10 has used batch scripts and scheduled tasks to delete critical system files.

T1078
Valid Accounts
GroupFIN10

FIN10 has used stolen credentials to connect remotely to victim networks using VPNs protected with only a single factor.

T1078.003
Local Accounts
GroupFIN10

FIN10 has moved laterally using the Local Administrator account.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN10

FIN10 has established persistence by using the Registry option in PowerShell Empire to add a Run key.

T1570
Lateral Tool Transfer
GroupFIN10

FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally.

T1588.002
Tool
GroupFIN10

FIN10 has relied on publicly-available software to gain footholds and establish persistence in victim environments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.