FIN6 — Ransomware Profile
FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Magecart Group 6, ITG08, Skeleton Spider, TAAL, Camouflage Tempest, White Giant, GOLD FRANKLIN, ATK88, G0037, TA4557, Storm-0538, SQUID COMET
Tools & malware
- AdFind Network Reconnaissance
- Cobalt Strike Adversary Simulation
- FlawedAmmyy Remote Access Trojan
- FrameworkPOS POS Malware
- GrimAgent Loader
- js.magecart Web Skimmer
- js.more_eggs Backdoor
- LockerGoga Ransomware
- Maze Ransomware
- Mimikatz Credential Harvesting
- More_eggs Backdoor
- PsExec Remote Execution
- Ryuk Ransomware
- win.cobalt_strike Adversary Simulation
- win.grateful_pos POS Malware
- win.lockergoga Ransomware
- win.maze Backdoor
- win.ryuk Ransomware
- win.terra_stealer Infostealer
- Windows Credential Editor Credential Harvesting
Vendor research
- Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware McKeague, B. et al
- How Microsoft names threat actors Microsoft
- ITG08 (aka FIN6) Partners With TrickBot Gang, Uses Anchor Framework Security Intelligence ITG08
- CrowdStrike 2018 Global Threat Report Crowdstrike
- Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware FireEye
- More_eggs, Anyone? Threat Actor ITG08 Strikes Again Security Intelligence More Eggs
- Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6 FireEye