news.mlab.sh
Threat intelligence
Threat actor

FIN6

Profile from actors.mlab.sh, coverage from our own index.

First seen
2015-01-01 00:00:00
Motivation
Financial crime, Financial gain
Targeted sectors
Chemical, Energy, Hospitality, Manufacturing, Retail
TLP
WHITE

FIN6 is a cybercrime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors. (FireEye) FIN6 is a cybercriminal group intent on stealing payment card data for monetization. In 2015, FireEye Threat Intelligence supported several Mandiant Consulting investigations in the hospitality and retail sectors where FIN6 actors had aggressively targeted and compromised point-of-sale (POS) systems, making off with millions of payment card numbers. Through iSIGHT, we learned that the payment card numbers stolen by FIN6 were sold on a “card shop” — an underground criminal marketplace used to sell or exchange payment card data.

Also known as

ATK 88Camouflage TempestFIN6G0037Gold FranklinITG08Magecart Group 6Skeleton SpiderStorm-0538TAALTAG-CR2White Giant

Vulnerabilities exploited

Tooling and malware

Cobalt StrikeFlawedAmmyyFrameworkPOSGrimAgentLockerGogaMazeMore_eggsRyukAdFindMimikatzPsExecWindows Credential Editor

MITRE ATT&CK techniques

T1005 Data from Local SystemT1119 Automated CollectionT1560 Archive Collected DataT1095 Non-Application Layer ProtocolT1102 Web ServiceT1572 Protocol TunnelingT1555 Credentials from Password StoresT1685 Disable or Modify ToolsT1018 Remote System DiscoveryT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1059 Command and Scripting InterpreterT1068 Exploitation for Privilege EscalationT1078 Valid AccountsT1134 Access Token Manipulation

Coverage 1