ATT&CKReferencesFireEye Know Your Enemy FIN8 Aug 2016

FireEye Know Your Enemy FIN8 Aug 2016

Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples33

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFIN8

FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE).

T1005
Data from Local System
MalwarePUNCHTRACK

PUNCHTRACK scrapes memory for properly formatted payment card data.

T1018
Remote System Discovery
GroupFIN8

FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used nltest.exe /dclist to retrieve a list of domain controllers.

T1021.001
Remote Desktop Protocol
GroupFIN8

FIN8 has used RDP for lateral movement.

T1021.002
SMB/Windows Admin Shares
GroupFIN8

FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement.

T1027.010
Command Obfuscation
GroupFIN8

FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads.

T1036.005
Match Legitimate Resource Name or Location
MalwarePUNCHBUGGY

PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%.

T1047
Windows Management Instrumentation
GroupFIN8

FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN8

FIN8 has used FTP to exfiltrate collected data.

T1053.005
Scheduled Task
GroupFIN8

FIN8 has used scheduled tasks to maintain RDP backdoors.

T1059.001
PowerShell
GroupFIN8

FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access.

T1059.003
Windows Command Shell
GroupFIN8

FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`.

T1068
Exploitation for Privilege Escalation
GroupFIN8

FIN8 has exploited the CVE-2016-0167 local vulnerability.

T1070.004
File Deletion
GroupFIN8

FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines.

T1070.004
File Deletion
MalwarePUNCHBUGGY

PUNCHBUGGY can delete files written to disk.

T1071.001
Web Protocols
MalwarePUNCHBUGGY

PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests.

T1074.001
Local Data Staging
MalwarePUNCHTRACK

PUNCHTRACK aggregates collected data in a tmp file.

T1074.002
Remote Data Staging
GroupFIN8

FIN8 aggregates staged data from a network into a single location.

T1078
Valid Accounts
GroupFIN8

FIN8 has used valid accounts for persistence and lateral movement.

T1105
Ingress Tool Transfer
MalwarePUNCHBUGGY

PUNCHBUGGY can download additional files and payloads to compromised hosts.

T1112
Modify Registry
GroupFIN8

FIN8 has deleted Registry keys during post compromise cleanup activities.

T1129
Shared Modules
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using the LoadLibrary API.

T1204.001
Malicious Link
GroupFIN8

FIN8 has used emails with malicious links to lure victims into installing malware.

T1204.002
Malicious File
GroupFIN8

FIN8 has used malicious e-mail attachments to lure victims into executing malware.

T1218.011
Rundll32
MalwarePUNCHBUGGY

PUNCHBUGGY can load a DLL using Rundll32.

T1518.001
Security Software Discovery
GroupFIN8

FIN8 has used Registry keys to detect and avoid executing in potential sandboxes.

T1546.009
AppCert DLLs
MalwarePUNCHBUGGY

PUNCHBUGGY can establish using a AppCertDLLs Registry key.

T1547.001
Registry Run Keys / Startup Folder
MalwarePUNCHBUGGY

PUNCHBUGGY has been observed using a Registry Run key.

T1560.001
Archive via Utility
GroupFIN8

FIN8 has used RAR to compress collected data before exfiltration.

T1566.001
Spearphishing Attachment
GroupFIN8

FIN8 has distributed targeted emails containing Word documents with embedded malicious macros.

T1566.002
Spearphishing Link
GroupFIN8

FIN8 has distributed targeted emails containing links to malicious documents with embedded macros.

T1573.002
Asymmetric Cryptography
GroupFIN8

FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure.

T1685.005
Clear Windows Event Logs
GroupFIN8

FIN8 has cleared logs during post compromise cleanup activities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.