Threat group.View on attack.mitre.org
FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at least 2013. FIN4 is unique in that they do not infect victims with typical persistent malware, but rather they focus on capturing credentials authorized to access email and other non-public correspondence.
| Technique | Procedure example |
|---|---|
| T1056.001 Keylogging |
FIN4 has captured credentials via fake Outlook Web App (OWA) login pages and has also used a .NET based keylogger. |
| T1056.002 GUI Input Capture |
FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. |
| T1059.005 Visual Basic |
FIN4 has used VBA macros to display a dialog box and collect victim credentials. |
| T1071.001 Web Protocols |
FIN4 has used HTTP POST requests to transmit data. |
| T1078 Valid Accounts |
FIN4 has used legitimate credentials to hijack email communications. |
| T1090.003 Multi-hop Proxy |
|
| T1114.002 Remote Email Collection |
FIN4 has accessed and hijacked online email communications using stolen credentials. |
| T1204.001 Malicious Link |
FIN4 has lured victims to click malicious links delivered via spearphishing emails (often sent from compromised accounts). |
| T1204.002 Malicious File |
FIN4 has lured victims to launch malicious attachments delivered via spearphishing emails (often sent from compromised accounts). |
| T1564.008 Email Hiding Rules |
FIN4 has created rules in victims' Microsoft Outlook accounts to automatically delete emails containing words such as “hacked," "phish," and “malware" in a likely attempt to prevent organizations from communicating about their activities. |
| T1566.001 Spearphishing Attachment |
FIN4 has used spearphishing emails containing attachments (which are often stolen, legitimate documents sent from compromised accounts) with embedded malicious macros. |
| T1566.002 Spearphishing Link |
FIN4 has used spearphishing emails (often sent from compromised accounts) containing malicious links. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.