FIN8
Aliases: Syssphinx
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.
Open interactive actor investigation
ATT&CK techniques
T1078
Valid AccountsT1070.001
Clear Windows Event LogsT1048.003
Exfiltration Over Unencrypted Non-C2 ProtocolT1033
System Owner/User DiscoveryT1518.001
Security Software DiscoveryT1021.001
Remote Desktop ProtocolT1003.001
LSASS MemoryT1588.002
ToolT1204.002
Malicious FileT1588.003
Code Signing CertificatesT1068
Exploitation for Privilege EscalationT1546.003
Windows Management Instrumentation Event SubscriptionT1566.002
Spearphishing LinkT1053.005
Scheduled TaskT1204.001
Malicious LinkT1102
Web ServiceT1027.010
Command ObfuscationT1070.004
File DeletionT1566.001
Spearphishing AttachmentT1071.001
Web ProtocolsT1021.002
SMB/Windows Admin SharesT1560.001
Archive via UtilityT1074.002
Remote Data StagingT1105
Ingress Tool TransferT1082
System Information DiscoveryT1059.001
PowerShellT1059.003
Windows Command ShellT1573.002
Asymmetric CryptographyT1055.004
Asynchronous Procedure CallT1018
Remote System DiscoveryT1486
Data Encrypted for ImpactT1482
Domain Trust DiscoveryT1112
Modify RegistryT1134.001
Token Impersonation/TheftT1016.001
Internet Connection DiscoveryT1047
Windows Management InstrumentationT1059
Command and Scripting Interpreter
Valid AccountsT1070.001
Clear Windows Event LogsT1048.003
Exfiltration Over Unencrypted Non-C2 ProtocolT1033
System Owner/User DiscoveryT1518.001
Security Software DiscoveryT1021.001
Remote Desktop ProtocolT1003.001
LSASS MemoryT1588.002
ToolT1204.002
Malicious FileT1588.003
Code Signing CertificatesT1068
Exploitation for Privilege EscalationT1546.003
Windows Management Instrumentation Event SubscriptionT1566.002
Spearphishing LinkT1053.005
Scheduled TaskT1204.001
Malicious LinkT1102
Web ServiceT1027.010
Command ObfuscationT1070.004
File DeletionT1566.001
Spearphishing AttachmentT1071.001
Web ProtocolsT1021.002
SMB/Windows Admin SharesT1560.001
Archive via UtilityT1074.002
Remote Data StagingT1105
Ingress Tool TransferT1082
System Information DiscoveryT1059.001
PowerShellT1059.003
Windows Command ShellT1573.002
Asymmetric CryptographyT1055.004
Asynchronous Procedure CallT1018
Remote System DiscoveryT1486
Data Encrypted for ImpactT1482
Domain Trust DiscoveryT1112
Modify RegistryT1134.001
Token Impersonation/TheftT1016.001
Internet Connection DiscoveryT1047
Windows Management InstrumentationT1059
Command and Scripting Interpreter