Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: FIN4, G0085

Description

FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at least 2013.(Citation: FireEye Hacking FIN4 Dec 2014)(Citation: FireEye FIN4 Stealing Insider NOV 2014) FIN4 is unique in that they do not infect victims with typical persistent malware, but rather they focus on capturing credentials authorized to access email and other non-public correspondence.(Citation: FireEye Hacking FIN4 Dec 2014)(Citation: FireEye Hacking FIN4 Video Dec 2014)

AI Analysis

· 1 week ago

Executive Summary

FIN4, also known as G0085, is a financially motivated threat group that has targeted sensitive information in the healthcare and pharmaceutical sectors since at least 2013. Unlike many APTs, FIN4 focuses on credential theft rather than deploying persistent malware, targeting authorized access to emails and non-public communications for financial gain.

Goals & Targeting

FIN4's primary motivation is financial gain, targeting industries where market-sensitive information can provide a competitive edge in trading activities. Their focus on healthcare and pharmaceutical companies suggests an interest in intellectual property, merger and acquisition activity, and other financially lucrative information. The group likely targets specific individuals within these sectors who have access to non-public communications, such as executives or employees involved in strategic decision-making.

Enhanced Description

FIN4 is a sophisticated financially motivated cyber threat group that has been active since at least 2013. The group primarily targets sensitive information related to public financial markets, particularly within the healthcare and pharmaceutical industries. Instead of using traditional malware infections, FIN4 specializes in capturing credentials from authorized users who have access to email accounts and other non-public communication channels. This unique approach allows them to exploit trusted user identities to gather valuable insider information. The group's operations are highly strategic, focusing on sectors with high financial stakes and sensitive data that can be monetized through insider trading or financial manipulation.

Key Capabilities

  • Credential harvesting via email compromise
  • Spearphishing campaigns targeting financial stakeholders
  • Email account compromise and unauthorized access
  • Use of keylogging and GUI input capture techniques
  • Multi-hop proxy chaining for C2 communication

MITRE ATT&CK Tactics

Credential Access
Email Collection
Spearphishing
Disruption
Exfiltration

ATT&CK Techniques

T1056.001: Keylogging
T1204.002: Malicious File
T1566.002: Spearphishing Link
T1114.002: Remote Email Collection
T1071.001: Web Protocols
T1204.001: Malicious Link
T1564.008: Email Hiding Rules
T1566.001: Spearphishing Attachment
T1056.002: GUI Input Capture
T1078: Valid Accounts
T1090.003: Multi-hop Proxy

Software / Tooling

Custom credential-harvesting tools
Spearphishing email templates
Multi-hop proxy chains
Email account compromise frameworks

Campaigns & Victims

FIN4 has demonstrated a sustained focus on the healthcare and pharmaceutical sectors, with activity spanning at least nine years. The group’s campaigns typically involve long-term surveillance and credential theft to gain access to email accounts of key personnel. Notable patterns include targeting during earnings announcements, mergers and acquisitions, and other market-moving events. FIN4's operational tempo is likely influenced by financial windows, such as quarterly reporting cycles.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • Email account compromises via credential theft
  • Use of multi-hop proxies for C2 communication
  • GUI input capture during login processes
  • Email header manipulation to hide sender information

Recommended Actions

  • Implement strong email authentication protocols (e.g., DMARC, SPF, DKIM)
  • Monitor for异常 login attempts from multiple geographic locations
  • Educate employees on recognizing spearphishing tactics
  • Use endpoint detection and response (EDR) tools to identify credential-harvesting activities
  • Conduct regular audits of access controls for email accounts with high-level information

Suggested Tags

Financially motivated APT
Healthcare Sector Targeting
Email Compromise
Credential Theft
Market manipulation risks

Confidence Assessment

Confidence in FIN4's details is moderate, with clear patterns and linked techniques identified. However, gaps exist regarding specific tools used and the full scope of their campaign history.

ATT&CK Techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. FireEye FIN4 Stealing Insider NOV 2014 — Dennesen, K. et al.. (2014, November 30). FIN4: Stealing Insider Information for an Advantage in Stock Trading?. Retrieved November 17, 2024.
  2. FireEye Hacking FIN4 Video Dec 2014 — Vengerik, B. & Dennesen, K.. (2014, December 5). Hacking the Street? FIN4 Likely Playing the Market. Retrieved January 15, 2019.
  3. FireEye Hacking FIN4 Dec 2014 — Vengerik, B. et al.. (2014, December 5). Hacking the Street? FIN4 Likely Playing the Market. Retrieved December 17, 2018.

Intel Summary

12

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

5

Tactics

Tags

Healthcare Targeting
Critical Infrastructure
Financially motivated APT
Healthcare Sector Targeting
Email Compromise
Credential Theft
Market manipulation risks

Details

MITRE ID
G0085
Type
Unknown
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--d0b3393b-3bec-4ba3-bda9-199d30db47b6
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.