FIN8

G0061

Threat group.View on attack.mitre.org

About this group

FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.

Techniques used36

Procedure examples36

TechniqueProcedure example
T1003.001
LSASS Memory

FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE).

T1016.001
Internet Connection Discovery

FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers.

T1018
Remote System Discovery

FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used nltest.exe /dclist to retrieve a list of domain controllers.

T1021.001
Remote Desktop Protocol

FIN8 has used RDP for lateral movement.

T1021.002
SMB/Windows Admin Shares

FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement.

T1027.010
Command Obfuscation

FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads.

T1033
System Owner/User Discovery

FIN8 has executed the command `quser` to display the session details of a compromised machine.

T1047
Windows Management Instrumentation

FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

FIN8 has used FTP to exfiltrate collected data.

T1053.005
Scheduled Task

FIN8 has used scheduled tasks to maintain RDP backdoors.

T1055.004
Asynchronous Procedure Call

FIN8 has injected malicious code into a new svchost.exe process.

T1059.001
PowerShell

FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access.

T1059.003
Windows Command Shell

FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`.

T1068
Exploitation for Privilege Escalation

FIN8 has exploited the CVE-2016-0167 local vulnerability.

T1070.004
File Deletion

FIN8 has deleted tmp and prefetch files during post compromise cleanup activities. FIN8 has also deleted PowerShell scripts to evade detection on compromised machines.

View all 36 procedure examples

Software11

Campaigns0

None recorded.

References4

  1. Bitdefender Sardonic Aug 2021 Open source
    Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.
  2. FireEye Fin8 May 2016 Open source
    Kizhakkinan, D., et al. (2016, May 11). Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks. Retrieved February 12, 2018.
  3. FireEye Obfuscation June 2017 Open source
    Bohannon, D. & Carr N. (2017, June 30). Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques. Retrieved February 12, 2018.
  4. Symantec FIN8 Jul 2023 Open source
    Symantec Threat Hunter Team. (2023, July 18). FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware. Retrieved August 9, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.