← threatfilter.dev / all groups / FIN8
FIN8
Also known as: Syssphinx
Overview
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.
Targets
Entertainment · Hospitality · Retail
Capabilities
- Custom malware/implant development — ATT&CK: 5 attributed custom malware families
TTPs — 36 techniques across 13 tactics
Resource Development
-
T1588.002Tool -
T1588.003Code Signing Certificates
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1204.001Malicious Link -
T1204.002Malicious File
Privilege Escalation
Stealth
-
T1027.010Command Obfuscation -
T1055.004Asynchronous Procedure Call -
T1070.004File Deletion -
T1078Valid Accounts -
T1134.001Token Impersonation/Theft
Defense Impairment
-
T1112Modify Registry -
T1685.005Clear Windows Event Logs
Credential Access
-
T1003.001LSASS Memory
Discovery
-
T1016.001Internet Connection Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1082System Information Discovery -
T1482Domain Trust Discovery -
T1518.001Security Software Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.002SMB/Windows Admin Shares
Collection
-
T1074.002Remote Data Staging -
T1560.001Archive via Utility
Command and Control
-
T1071.001Web Protocols -
T1102Web Service -
T1105Ingress Tool Transfer -
T1573.002Asymmetric Cryptography
Exfiltration
Impact
Tools & malware (11)
Ping · BADHATCH · PUNCHBUGGY · Ragnar Locker · PUNCHTRACK · dsquery · Net · Nltest · Sardonic · PsExec · Impacket
Reporting (3)
- FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware — Symantec Threat Hunter Team
- FIN8 Threat Actor Goes Agile with New Sardonic Backdoor — Budaca, E., et al
- Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques — Bohannon, D. & Carr N