FIN8
Also known as: Syssphinx
Overview
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.
Naming & attribution
FIN8 is tracked under 2 names across the industry. It uses 36 documented ATT&CK techniques — more than 72% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Syssphinx | Symantec Threat Hunter Team |
| FIN8 | Bohannon, D. & Carr N |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1055.004Asynchronous Procedure Call — used by 1 of 174 groups -
T1134.001Token Impersonation/Theft — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Wizard Spider Russia — 25 shared techniques (33% overlap)
- FIN6 — 18 shared techniques (31% overlap)
- Cobalt Group — 16 shared techniques (30% overlap)
- Aquatic Panda China — 16 shared techniques (29% overlap)
- APT33 Iran — 15 shared techniques (29% overlap)
- Play — 14 shared techniques (29% overlap)
Malware families with current indicators
One family attributed to FIN8, carrying 21 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- RagnarLocker 21 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Targets
Entertainment · Hospitality · Retail
Capabilities
- Custom malware/implant development — ATT&CK: 5 attributed custom malware families
TTPs — 36 techniques across 13 tactics
Resource Development
-
T1588.002Tool -
T1588.003Code Signing Certificates
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1204.001Malicious Link -
T1204.002Malicious File
Privilege Escalation
Stealth
-
T1027.010Command Obfuscation -
T1055.004Asynchronous Procedure Call -
T1070.004File Deletion -
T1078Valid Accounts -
T1134.001Token Impersonation/Theft
Defense Impairment
-
T1112Modify Registry -
T1685.005Clear Windows Event Logs
Credential Access
-
T1003.001LSASS Memory
Discovery
-
T1016.001Internet Connection Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1082System Information Discovery -
T1482Domain Trust Discovery -
T1518.001Security Software Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares
Collection
-
T1074.002Remote Data Staging -
T1560.001Archive via Utility
Command and Control
-
T1071.001Web Protocols -
T1102Web Service -
T1105Ingress Tool Transfer -
T1573.002Asymmetric Cryptography
Exfiltration
Impact
Tools & malware (11)
Ping · BADHATCH · PUNCHBUGGY · Ragnar Locker · PUNCHTRACK · dsquery · Net · Nltest · Sardonic · PsExec · Impacket
Reporting (3)
- FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware — Symantec Threat Hunter Team
- FIN8 Threat Actor Goes Agile with New Sardonic Backdoor — Budaca, E., et al
- Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques — Bohannon, D. & Carr N