FireEye Threat Intelligence. (2016, April). Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6. Retrieved November 17, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupFIN6 | FIN6 has used Windows Credential Editor for credential dumping. |
| T1003.003 NTDS |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1018 Remote System Discovery |
GroupFIN6 | FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1021.001 Remote Desktop Protocol |
GroupFIN6 | FIN6 used RDP to move laterally in victim networks. |
| T1046 Network Service Discovery |
GroupFIN6 | FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS. |
| T1053.005 Scheduled Task |
GroupFIN6 | FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS. |
| T1059 Command and Scripting Interpreter |
GroupFIN6 | FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files. |
| T1059.001 PowerShell |
GroupFIN6 | FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener. |
| T1068 Exploitation for Privilege Escalation |
GroupFIN6 | FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges. |
| T1070.004 File Deletion |
GroupFIN6 | FIN6 has removed files from victim machines. |
| T1074.001 Local Data Staging |
MalwareFrameworkPOS | FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows\. |
| T1074.002 Remote Data Staging |
GroupFIN6 | FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration. |
| T1078 Valid Accounts |
GroupFIN6 | To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes. |
| T1087.002 Domain Account |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1110.002 Password Cracking |
GroupFIN6 | FIN6 has extracted password hashes from ntds.dit to crack offline. |
| T1119 Automated Collection |
GroupFIN6 | FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupFIN6 | FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD. |
| T1560 Archive Collected Data |
GroupFIN6 | Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration. |
| T1560.003 Archive via Custom Method |
GroupFIN6 | FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation. |
| T1572 Protocol Tunneling |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
| T1573.002 Asymmetric Cryptography |
GroupFIN6 | FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.