Financial Theft

T1657

Technique.View on attack.mitre.org

About this technique

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Adversaries may Compromise Accounts to conduct unauthorized transfers of funds. In the case of business email compromise or email fraud, an adversary may utilize Impersonation of a trusted entity. Once the social engineering is successful, victims can be deceived into sending money to financial accounts controlled by an adversary. This creates the potential for multiple victims (i.e., compromised accounts as well as the ultimate monetary loss) in incidents involving financial theft.

Extortion by ransomware may occur, for example, when an adversary demands payment from a victim after Data Encrypted for Impact and Exfiltration of data, followed by threatening to leak sensitive data to the public unless payment is made to the adversary. Adversaries may use dedicated leak sites to distribute victim data.

Due to the potentially immense business impact of financial theft, an adversary may abuse the possibility of financial theft and seeking monetary gain to divert attention from their true goals such as Data Destruction and business disruption.

Detection rules0

Rules on DetectionCode tagged with T1657.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups17

Software8

Campaigns1

Procedure examples26

Groups17

Used byProcedure example
GroupAkira

Akira engages in double-extortion ransomware, exfiltrating files then encrypting them, in order to prompt victims to pay a ransom.

GroupAppleJeus

AppleJeus has targeted the cryptocurrency industry with the goal of stealing digital assets.

GroupCinnamon Tempest

Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom.

GroupContagious Interview

Contagious Interview has stolen cryptocurrency wallet credentials and credit card information utilizing BeaverTail and InvisibleFerret malware.

GroupFIN13

FIN13 has observed the victim's software and infrastructure over several months to understand the technical process of legitimate financial transactions, prior to attempting to conduct fraudulent transactions.

GroupINC Ransom

INC Ransom has stolen and encrypted victim's data in order to extort payment for keeping it private or decrypting it.

GroupKimsuky

Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure.

GroupMalteiro

Malteiro targets organizations in a wide variety of sectors via the use of Mispadu banking trojan with the goal of financial theft.

View all 17 groups examples

Software8

Used byProcedure example
MalwareBeaverTail

BeaverTail has searched the victim device for browser extensions commonly associated with cryptocurrency wallets.

MalwareCrocodilus

Crocodilus has stolen cryptocurrency wallet details from victim devices.

MalwareDarkGate

DarkGate can deploy payloads capable of capturing credentials related to cryptocurrency wallets.

MalwareEmbargo

Embargo has been leveraged in double-extortion ransomware, exfiltrating files then encrypting them, to prompt victims to pay a ransom.

MalwareGlassWorm

GlassWorm has the ability to steal credentials for cryptocurrency wallets.

MalwareInvisibleFerret

InvisibleFerret has searched the victim device credentials and files commonly associated with cryptocurrency wallets.

MalwareRedLine Stealer

RedLine Stealer has collected data from cryptocurrency wallets and harvested credit cards details from browsers.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can search filesystems for cryptocurrency wallets such as Bitcoin, Litecoin, Dogecoin, Zcash, Dash, Ripple, and Monero.

Campaigns1

Used byProcedure example
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors demanded ransom payments to unencrypt filesystems and to refrain from publishing sensitive data exfiltrated from victim networks.

References11

  1. AP-NotPetya Open source
    FRANK BAJAK AND RAPHAEL SATTER. (2017, June 30). Companies still hobbled from fearsome cyberattack. Retrieved August 18, 2023.
  2. BBC-Ronin Open source
    Joe Tidy. (2022, March 30). Ronin Network: What a $600m hack says about the state of crypto. Retrieved August 18, 2023.
  3. Crowdstrike-leaks Open source
    Crowdstrike. (2020, September 24). Double Trouble: Ransomware with Data Leak Extortion, Part 1. Retrieved December 6, 2023.
  4. DOJ-DPRK Heist Open source
    Department of Justice. (2021). 3 North Korean Military Hackers Indicted in Wide-Ranging Scheme to Commit Cyber-attacks and Financial Crimes Across the Globe. Retrieved August 18, 2023.
  5. FBI-BEC Open source
    FBI. (2022). FBI 2022 Congressional Report on BEC and Real Estate Wire Fraud. Retrieved August 18, 2023.
  6. FBI-ransomware Open source
    FBI. (n.d.). Ransomware. Retrieved August 18, 2023.
  7. Internet crime report 2022 Open source
    IC3. (2022). 2022 Internet Crime Report. Retrieved August 18, 2023.
  8. Mandiant-leaks Open source
    DANIEL KAPELLMANN ZAFRA, COREY HIDELBRANDT, NATHAN BRUBAKER, KEITH LUNDEN. (2022, January 31). 1 in 7 OT Ransomware Extortion Attacks Leak Critical Operational Technology Information. Retrieved August 18, 2023.
  9. NYT-Colonial Open source
    Nicole Perlroth. (2021, May 13). Colonial Pipeline paid 75 Bitcoin, or roughly $5 million, to hackers.. Retrieved August 18, 2023.
  10. VEC Open source
    CloudFlare. (n.d.). What is vendor email compromise (VEC)?. Retrieved September 12, 2023.
  11. wired-pig butchering Open source
    Lily Hay Newman. (n.d.). ‘Pig Butchering’ Scams Are Now a $3 Billion Threat. Retrieved August 18, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.