NEW: Group Profiler — instant APT intel lookup. Try it →

FIN4

Overview

FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at least 2013. FIN4 is unique in that they do not infect victims with typical persistent malware, but rather they focus on capturing credentials authorized to access email and other non-public correspondence.

Naming & attribution

FIN4 is tracked under 1 names across the industry. It uses 12 documented ATT&CK techniques — more than 35% of the 174 groups tracked here. Activity attributed since at least 2013.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
FIN4Vengerik, B. et al.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1056.002 GUI Input Capture — used by 2 of 174 groups
  • T1564.008 Email Hiding Rules — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Mofang China — 4 shared techniques (29% overlap)
  • Machete — 5 shared techniques (28% overlap)
  • Confucius — 6 shared techniques (24% overlap)
  • Windshift — 6 shared techniques (24% overlap)
  • Transparent Tribe Pakistan — 5 shared techniques (24% overlap)
  • Elderwood China — 4 shared techniques (24% overlap)

Targets

Finance · Healthcare · Pharmacy

TTPs — 12 techniques across 5 tactics

Initial Access

Execution

Stealth

Collection

Command and Control

Reporting (3)