McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupFIN6 | FIN6 has used Windows Credential Editor for credential dumping. |
| T1003.003 NTDS |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1016 System Network Configuration Discovery |
ToolAdFind | AdFind can extract subnet information from Active Directory. |
| T1018 Remote System Discovery |
ToolAdFind | AdFind has the ability to query Active Directory for computers. |
| T1021.001 Remote Desktop Protocol |
GroupFIN6 | FIN6 used RDP to move laterally in victim networks. |
| T1036.004 Masquerade Task or Service |
GroupFIN6 | FIN6 has renamed the "psexec" service name to "mstdc" to masquerade as a legitimate Windows service. |
| T1059 Command and Scripting Interpreter |
GroupFIN6 | FIN6 has used scripting to iterate through a list of compromised PoS systems, copy data to a log file, and remove the original data files. |
| T1059.001 PowerShell |
GroupFIN6 | FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener. |
| T1059.003 Windows Command Shell |
GroupFIN6 | FIN6 has used |
| T1069.002 Domain Groups |
ToolAdFind | AdFind can enumerate domain groups. |
| T1078 Valid Accounts |
GroupFIN6 | To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes. |
| T1087.002 Domain Account |
ToolAdFind | AdFind can enumerate domain users. |
| T1102 Web Service |
GroupFIN6 | FIN6 has used Pastebin and Google Storage to host content for their operations. |
| T1134 Access Token Manipulation |
GroupFIN6 | FIN6 has used has used Metasploit’s named-pipe impersonation technique to escalate privileges. |
| T1482 Domain Trust Discovery |
ToolAdFind | AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory. |
| T1569.002 Service Execution |
GroupFIN6 | FIN6 has created Windows services to execute encoded PowerShell commands. |
| T1588.002 Tool |
GroupFIN6 | FIN6 has obtained and used tools such as Mimikatz, Cobalt Strike, and AdFind. |
| T1685 Disable or Modify Tools |
GroupFIN6 | FIN6 has deployed a utility script named |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.