FIN8 — Ransomware Profile
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Syssphinx, ATK113, G0061, PUNCH COMET
Tools & malware
- BADHATCH Backdoor
- dsquery Network Reconnaissance
- Impacket Network Toolkit
- Net Network Reconnaissance
- Nltest Network Reconnaissance
- Ping Network Reconnaissance
- PsExec Remote Execution
- PUNCHBUGGY Downloader
- PUNCHTRACK POS Malware
- Ragnar Locker Ransomware
- Sardonic Backdoor
Vendor research
- Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks Kizhakkinan, D., et al
- Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques FireEye
- FIN8 Threat Actor Goes Agile with New Sardonic Backdoor Bitdefender
- FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware Symantec
- Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks FireEye
Countries linked to this actor
- South Africa targets