ATT&CKReferencesMandiant FIN13 Aug 2022

Mandiant FIN13 Aug 2022

Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples34

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFIN13

FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz.

T1005
Data from Local System
GroupFIN13

FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.

T1016
System Network Configuration Discovery
GroupFIN13

FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information.

T1016.001
Internet Connection Discovery
GroupFIN13

FIN13 has used `Ping` and `tracert` for network reconnaissance efforts.

T1021.001
Remote Desktop Protocol
GroupFIN13

FIN13 has remotely accessed compromised environments via Remote Desktop Services (RDS) for lateral movement.

T1021.004
SSH
GroupFIN13

FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement.

T1036
Masquerading
GroupFIN13

FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file.

T1036.004
Masquerade Task or Service
GroupFIN13

FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory.

T1046
Network Service Discovery
GroupFIN13

FIN13 has utilized `nmap` for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network.

T1047
Windows Management Instrumentation
GroupFIN13

FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines.

T1049
System Network Connections Discovery
GroupFIN13

FIN13 has used `netstat` and other net commands for network reconnaissance efforts.

T1053.005
Scheduled Task
GroupFIN13

FIN13 has created scheduled tasks in the `C:\Windows` directory of the compromised network.

T1056.001
Keylogging
GroupFIN13

FIN13 has logged the keystrokes of victims to escalate privileges.

T1059.001
PowerShell
GroupFIN13

FIN13 has used PowerShell commands to obtain DNS data from a compromised network.

T1059.003
Windows Command Shell
GroupFIN13

FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers.

T1069
Permission Groups Discovery
GroupFIN13

FIN13 has enumerated all users and roles from a victim's main treasury system.

T1071.001
Web Protocols
GroupFIN13

FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data.

T1074.001
Local Data Staging
GroupFIN13

FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`.

T1082
System Information Discovery
GroupFIN13

FIN13 has collected local host information by utilizing Windows commands `systeminfo`, `fsutil`, and `fsinfo`. FIN13 has also utilized a compromised Symantex Altiris console and LanDesk account to retrieve host information.

T1083
File and Directory Discovery
GroupFIN13

FIN13 has used the Windows `dir` command to enumerate files and directories in a victim's network.

T1087
Account Discovery
GroupFIN13

FIN13 has enumerated all users and their roles from a victim's main treasury system.

T1087.002
Domain Account
GroupFIN13

FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`.

T1105
Ingress Tool Transfer
GroupFIN13

FIN13 has downloaded additional tools and malware to compromised systems.

T1133
External Remote Services
GroupFIN13

FIN13 has gained access to compromised environments via remote access services such as the corporate virtual private network (VPN).

T1135
Network Share Discovery
GroupFIN13

FIN13 has executed net view commands for enumeration of open shares on compromised machines.

T1140
Deobfuscate/Decode Files or Information
GroupFIN13

FIN13 has utilized `certutil` to decode base64 encoded versions of custom malware.

T1190
Exploit Public-Facing Application
GroupFIN13

FIN13 has exploited known vulnerabilities such as CVE-2017-1000486 (Primefaces Application Expression Language Injection), CVE-2015-7450 (WebSphere Application Server SOAP Deserialization Exploit), CVE-2010-5326 (SAP NewWeaver Invoker Servlet Exploit), and EDB-ID-24963 (SAP NetWeaver ConfigServlet Remote Code Execution) to gain initial access.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN13

FIN13 has used Windows Registry run keys such as, `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\hosts` to maintain persistence.

T1550.002
Pass the Hash
GroupFIN13

FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment.

T1556
Modify Authentication Process
GroupFIN13

FIN13 has replaced legitimate KeePass binaries with trojanized versions to collect passwords from numerous applications.

T1564.001
Hidden Files and Directories
GroupFIN13

FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information.

T1587.001
Malware
GroupFIN13

FIN13 has utilized custom malware to maintain persistence in a compromised environment.

T1589
Gather Victim Identity Information
GroupFIN13

FIN13 has researched employees to target for social engineering attacks.

T1590.004
Network Topology
GroupFIN13

FIN13 has searched for infrastructure that can provide remote access to an environment for targeting efforts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.