NEW: Group Profiler — instant APT intel lookup. Try it →

FIN8

Also known as: Syssphinx

Overview

FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.

Naming & attribution

FIN8 is tracked under 2 names across the industry. It uses 36 documented ATT&CK techniques — more than 72% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
SyssphinxSymantec Threat Hunter Team
FIN8Bohannon, D. & Carr N

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1055.004 Asynchronous Procedure Call — used by 1 of 174 groups
  • T1134.001 Token Impersonation/Theft — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Wizard Spider Russia — 25 shared techniques (33% overlap)
  • FIN6 — 18 shared techniques (31% overlap)
  • Cobalt Group — 16 shared techniques (30% overlap)
  • Aquatic Panda China — 16 shared techniques (29% overlap)
  • APT33 Iran — 15 shared techniques (29% overlap)
  • Play — 14 shared techniques (29% overlap)

Malware families with current indicators

One family attributed to FIN8, carrying 21 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • RagnarLocker 21 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Entertainment · Hospitality · Retail

Capabilities

  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 36 techniques across 13 tactics

Resource Development

Initial Access

Execution

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Tools & malware (11)

Ping · BADHATCH · PUNCHBUGGY · Ragnar Locker · PUNCHTRACK · dsquery · Net · Nltest · Sardonic · PsExec · Impacket

Reporting (3)