ATT&CKReferencesFireEye Fin8 May 2016

FireEye Fin8 May 2016

Kizhakkinan, D., et al. (2016, May 11). Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks. Retrieved February 12, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwarePUNCHTRACK

PUNCHTRACK scrapes memory for properly formatted payment card data.

T1027
Obfuscated Files or Information
MalwarePUNCHTRACK

PUNCHTRACK is loaded and executed by a highly obfuscated launcher.

T1068
Exploitation for Privilege Escalation
GroupFIN8

FIN8 has exploited the CVE-2016-0167 local vulnerability.

T1071.001
Web Protocols
MalwarePUNCHBUGGY

PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests.

T1105
Ingress Tool Transfer
GroupFIN8

FIN8 has used remote code execution to download subsequent payloads.

T1204.001
Malicious Link
GroupFIN8

FIN8 has used emails with malicious links to lure victims into installing malware.

T1204.002
Malicious File
GroupFIN8

FIN8 has used malicious e-mail attachments to lure victims into executing malware.

T1566.001
Spearphishing Attachment
GroupFIN8

FIN8 has distributed targeted emails containing Word documents with embedded malicious macros.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.