Visa Public. (2019, February). FIN6 Cybercrime Group Expands Threat to eCommerce Merchants. Retrieved September 16, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
GroupFIN6 | FIN6 has used encoded PowerShell commands. |
| T1059.001 PowerShell |
GroupFIN6 | FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener. |
| T1078 Valid Accounts |
GroupFIN6 | To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes. |
| T1204.002 Malicious File |
GroupFIN6 | FIN6 has used malicious documents to lure victims into allowing execution of PowerShell scripts. |
| T1213.006 Databases |
GroupFIN6 | FIN6 has collected schemas and user accounts from systems running SQL Server. |
| T1555 Credentials from Password Stores |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP. |
| T1555.003 Credentials from Web Browsers |
GroupFIN6 | FIN6 has used the Stealer One credential stealer to target web browsers. |
| T1566.001 Spearphishing Attachment |
GroupFIN6 | FIN6 has targeted victims with e-mails containing malicious attachments. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.