ATT&CKReferencesBitdefender FIN8 July 2021

Bitdefender FIN8 July 2021

Martin Zugec. (2021, July 27). Deep Dive Into a FIN8 Attack - A Forensic Investigation. Retrieved September 1, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1018
Remote System Discovery
GroupFIN8

FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used nltest.exe /dclist to retrieve a list of domain controllers.

T1027.010
Command Obfuscation
GroupFIN8

FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads.

T1047
Windows Management Instrumentation
GroupFIN8

FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.

T1055.004
Asynchronous Procedure Call
GroupFIN8

FIN8 has injected malicious code into a new svchost.exe process.

T1059.001
PowerShell
GroupFIN8

FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access.

T1059.003
Windows Command Shell
GroupFIN8

FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`.

T1071.001
Web Protocols
GroupFIN8

FIN8 has used HTTPS for command and control.

T1102
Web Service
GroupFIN8

FIN8 has used sslip.io, a free IP to domain mapping service that also makes SSL certificate generation easier for traffic encryption, as part of their command and control.

T1105
Ingress Tool Transfer
GroupFIN8

FIN8 has used remote code execution to download subsequent payloads.

T1134.001
Token Impersonation/Theft
GroupFIN8

FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token.

T1482
Domain Trust Discovery
GroupFIN8

FIN8 has retrieved a list of trusted domains by using nltest.exe /domain_trusts.

T1546.003
Windows Management Instrumentation Event Subscription
GroupFIN8

FIN8 has used WMI event subscriptions for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.