Chen, J. (2019, October 10). Magecart Card Skimmers Injected Into Online Shops. Retrieved September 9, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupFIN6 | FIN6 has collected and exfiltrated payment card data from compromised systems. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupFIN6 | FIN6 has sent stolen payment card data to remote servers via HTTP POSTs. |
| T1059.007 JavaScript |
GroupFIN6 | FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites. |
| T1095 Non-Application Layer Protocol |
GroupFIN6 | FIN6 has used Metasploit Bind and Reverse TCP stagers. |
| T1119 Automated Collection |
GroupFIN6 | FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button. |
| T1560.003 Archive via Custom Method |
GroupFIN6 | FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.