Threat intelligence
- First seen
- 2015-01-01 00:00:00
- Motivation
- Financial crime, Financial gain
- Targeted sectors
- Chemical, Energy, Hospitality, Manufacturing, Retail
- TLP
- WHITE
FIN6 is a cybercrime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.
(FireEye) FIN6 is a cybercriminal group intent on stealing payment card data for monetization. In 2015, FireEye Threat Intelligence supported several Mandiant Consulting investigations in the hospitality and retail sectors where FIN6 actors had aggressively targeted and compromised point-of-sale (POS) systems, making off with millions of payment card numbers. Through iSIGHT, we learned that the payment card numbers stolen by FIN6 were sold on a “card shop” — an underground criminal marketplace used to sell or exchange payment card data.
Also known as
ATK 88Camouflage TempestFIN6G0037Gold FranklinITG08Magecart Group 6Skeleton SpiderStorm-0538TAALTAG-CR2White Giant
Vulnerabilities exploited
Tooling and malware
Cobalt StrikeFlawedAmmyyFrameworkPOSGrimAgentLockerGogaMazeMore_eggsRyukAdFindMimikatzPsExecWindows Credential Editor
MITRE ATT&CK techniques
T1005 Data from Local SystemT1119 Automated CollectionT1560 Archive Collected DataT1095 Non-Application Layer ProtocolT1102 Web ServiceT1572 Protocol TunnelingT1555 Credentials from Password StoresT1685 Disable or Modify ToolsT1018 Remote System DiscoveryT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1059 Command and Scripting InterpreterT1068 Exploitation for Privilege EscalationT1078 Valid AccountsT1134 Access Token Manipulation
Coverage 1
threat-intel
The Golden Chickens malware-as-a-service (MaaS) group, tracked as TAG-195, has resurfaced with four new malware families, indicating continued development and a shift towards a more flexible, modular approach to evade de…
