Elovitz, S. & Ahl, I. (2016, August 18). Know Your Enemy: New Financially-Motivated & Spear-Phishing Group. Retrieved February 26, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupFIN8 | FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE). |
| T1005 Data from Local System |
MalwarePUNCHTRACK | PUNCHTRACK scrapes memory for properly formatted payment card data. |
| T1018 Remote System Discovery |
GroupFIN8 | FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used |
| T1021.001 Remote Desktop Protocol |
GroupFIN8 | FIN8 has used RDP for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupFIN8 | FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement. |
| T1027.010 Command Obfuscation |
GroupFIN8 | FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwarePUNCHBUGGY | PUNCHBUGGY mimics filenames from %SYSTEM%\System32 to hide DLLs in %WINDIR% and/or %TEMP%. |
| T1047 Windows Management Instrumentation |
GroupFIN8 | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN8 | FIN8 has used FTP to exfiltrate collected data. |
| T1053.005 Scheduled Task |
GroupFIN8 | FIN8 has used scheduled tasks to maintain RDP backdoors. |
| T1059.001 PowerShell |
GroupFIN8 | FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access. |
| T1059.003 Windows Command Shell |
GroupFIN8 | FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN8 | FIN8 has exploited the CVE-2016-0167 local vulnerability. |
| T1070.004 File Deletion |
GroupFIN8 | FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines. |
| T1070.004 File Deletion |
MalwarePUNCHBUGGY | PUNCHBUGGY can delete files written to disk. |
| T1071.001 Web Protocols |
MalwarePUNCHBUGGY | PUNCHBUGGY enables remote interaction and can obtain additional code over HTTPS GET and POST requests. |
| T1074.001 Local Data Staging |
MalwarePUNCHTRACK | PUNCHTRACK aggregates collected data in a tmp file. |
| T1074.002 Remote Data Staging |
GroupFIN8 | FIN8 aggregates staged data from a network into a single location. |
| T1078 Valid Accounts |
GroupFIN8 | FIN8 has used valid accounts for persistence and lateral movement. |
| T1105 Ingress Tool Transfer |
MalwarePUNCHBUGGY | PUNCHBUGGY can download additional files and payloads to compromised hosts. |
| T1112 Modify Registry |
GroupFIN8 | FIN8 has deleted Registry keys during post compromise cleanup activities. |
| T1129 Shared Modules |
MalwarePUNCHBUGGY | PUNCHBUGGY can load a DLL using the LoadLibrary API. |
| T1204.001 Malicious Link |
GroupFIN8 | FIN8 has used emails with malicious links to lure victims into installing malware. |
| T1204.002 Malicious File |
GroupFIN8 | FIN8 has used malicious e-mail attachments to lure victims into executing malware. |
| T1218.011 Rundll32 |
MalwarePUNCHBUGGY | PUNCHBUGGY can load a DLL using Rundll32. |
| T1518.001 Security Software Discovery |
GroupFIN8 | FIN8 has used Registry keys to detect and avoid executing in potential sandboxes. |
| T1546.009 AppCert DLLs |
MalwarePUNCHBUGGY | PUNCHBUGGY can establish using a AppCertDLLs Registry key. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwarePUNCHBUGGY | PUNCHBUGGY has been observed using a Registry Run key. |
| T1560.001 Archive via Utility |
GroupFIN8 | FIN8 has used RAR to compress collected data before exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupFIN8 | FIN8 has distributed targeted emails containing Word documents with embedded malicious macros. |
| T1566.002 Spearphishing Link |
GroupFIN8 | FIN8 has distributed targeted emails containing links to malicious documents with embedded macros. |
| T1573.002 Asymmetric Cryptography |
GroupFIN8 | FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure. |
| T1685.005 Clear Windows Event Logs |
GroupFIN8 | FIN8 has cleared logs during post compromise cleanup activities. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.