ATT&CKReferencesVisa FIN6 Feb 2019

Visa FIN6 Feb 2019

Visa Public. (2019, February). FIN6 Cybercrime Group Expands Threat to eCommerce Merchants. Retrieved September 16, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupFIN6

FIN6 has used encoded PowerShell commands.

T1059.001
PowerShell
GroupFIN6

FIN6 has used PowerShell to gain access to merchant's networks, and a Metasploit PowerShell module to download and execute shellcode and to set up a local listener.

T1078
Valid Accounts
GroupFIN6

To move laterally on a victim network, FIN6 has used credentials stolen from various systems on which it gathered usernames and password hashes.

T1204.002
Malicious File
GroupFIN6

FIN6 has used malicious documents to lure victims into allowing execution of PowerShell scripts.

T1213.006
Databases
GroupFIN6

FIN6 has collected schemas and user accounts from systems running SQL Server.

T1555
Credentials from Password Stores
GroupFIN6

FIN6 has used the Stealer One credential stealer to target e-mail and file transfer utilities including FTP.

T1555.003
Credentials from Web Browsers
GroupFIN6

FIN6 has used the Stealer One credential stealer to target web browsers.

T1566.001
Spearphishing Attachment
GroupFIN6

FIN6 has targeted victims with e-mails containing malicious attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.