ATT&CKReferencesFireEye FIN6 April 2016

FireEye FIN6 April 2016

FireEye Threat Intelligence. (2016, April). Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples21

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupFIN6

FIN6 has used Windows Credential Editor for credential dumping.

T1003.003
NTDS
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1018
Remote System Discovery
GroupFIN6

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1021.001
Remote Desktop Protocol
GroupFIN6

FIN6 used RDP to move laterally in victim networks.

T1046
Network Service Discovery
GroupFIN6

FIN6 used publicly available tools (including Microsoft's built-in SQL querying tool, osql.exe) to map the internal network and conduct reconnaissance against Active Directory, Structured Query Language (SQL) servers, and NetBIOS.

T1053.005
Scheduled Task
GroupFIN6

FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS.

T1059
Command and Scripting Interpreter
GroupFIN6

FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files.

T1059.001
PowerShell
GroupFIN6

FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener.

T1068
Exploitation for Privilege Escalation
GroupFIN6

FIN6 has used tools to exploit Windows vulnerabilities in order to escalate privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398, all of which could allow local users to access kernel-level privileges.

T1070.004
File Deletion
GroupFIN6

FIN6 has removed files from victim machines.

T1074.001
Local Data Staging
MalwareFrameworkPOS

FrameworkPOS can identifiy payment card track data on the victim and copy it to a local file in a subdirectory of C:\Windows\.

T1074.002
Remote Data Staging
GroupFIN6

FIN6 actors have compressed data from remote systems and moved it to another staging system before exfiltration.

T1078
Valid Accounts
GroupFIN6

To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes.

T1087.002
Domain Account
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1110.002
Password Cracking
GroupFIN6

FIN6 has extracted password hashes from ntds.dit to crack offline.

T1119
Automated Collection
GroupFIN6

FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button.

T1547.001
Registry Run Keys / Startup Folder
GroupFIN6

FIN6 has used Registry Run keys to establish persistence for its downloader tools known as HARDTACK and SHIPBREAD.

T1560
Archive Collected Data
GroupFIN6

Following data collection, FIN6 has compressed log files into a ZIP archive prior to staging and exfiltration.

T1560.003
Archive via Custom Method
GroupFIN6

FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation.

T1572
Protocol Tunneling
GroupFIN6

FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers.

T1573.002
Asymmetric Cryptography
GroupFIN6

FIN6 used the Plink command-line utility to create SSH tunnels to C2 servers.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.