ATT&CKReferencesTrend Micro FIN6 October 2019

Trend Micro FIN6 October 2019

Chen, J. (2019, October 10). Magecart Card Skimmers Injected Into Online Shops. Retrieved September 9, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupFIN6

FIN6 has collected and exfiltrated payment card data from compromised systems.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
GroupFIN6

FIN6 has sent stolen payment card data to remote servers via HTTP POSTs.

T1059.007
JavaScript
GroupFIN6

FIN6 has used malicious JavaScript to steal payment card data from e-commerce sites.

T1095
Non-Application Layer Protocol
GroupFIN6

FIN6 has used Metasploit Bind and Reverse TCP stagers.

T1119
Automated Collection
GroupFIN6

FIN6 has used a script to iterate through a list of compromised PoS systems, copy and remove data to a log file, and to bind to events from the submit payment button.

T1560.003
Archive via Custom Method
GroupFIN6

FIN6 has encoded data gathered from the victim with a simple substitution cipher and single-byte XOR using the 0xAA key, and Base64 with character permutation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.