Martin Zugec. (2021, July 27). Deep Dive Into a FIN8 Attack - A Forensic Investigation. Retrieved September 1, 2021.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
GroupFIN8 | FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used |
| T1027.010 Command Obfuscation |
GroupFIN8 | FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads. |
| T1047 Windows Management Instrumentation |
GroupFIN8 | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities. |
| T1055.004 Asynchronous Procedure Call |
GroupFIN8 | FIN8 has injected malicious code into a new svchost.exe process. |
| T1059.001 PowerShell |
GroupFIN8 | FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access. |
| T1059.003 Windows Command Shell |
GroupFIN8 | FIN8 has used a Batch file to automate frequently executed post compromise cleanup activities. FIN8 has also executed commands remotely via `cmd.exe`. |
| T1071.001 Web Protocols |
GroupFIN8 | FIN8 has used HTTPS for command and control. |
| T1102 Web Service |
GroupFIN8 | FIN8 has used |
| T1105 Ingress Tool Transfer |
GroupFIN8 | FIN8 has used remote code execution to download subsequent payloads. |
| T1134.001 Token Impersonation/Theft |
GroupFIN8 | FIN8 has used a malicious framework designed to impersonate the lsass.exe/vmtoolsd.exe token. |
| T1482 Domain Trust Discovery |
GroupFIN8 | FIN8 has retrieved a list of trusted domains by using |
| T1546.003 Windows Management Instrumentation Event Subscription |
GroupFIN8 | FIN8 has used WMI event subscriptions for persistence. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.