Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Magecart Group 6, ITG08, Skeleton Spider, TAAL, Camouflage Tempest, FIN6, White Giant, GOLD FRANKLIN, ATK88, G0037, TA4557, Storm-0538, SQUID COMET

Description

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.(Citation: FireEye FIN6 April 2016)(Citation: FireEye FIN6 Apr 2019)

AI Analysis

· 1 week ago

Executive Summary

FIN6, also known as Magecart Group 6, is a cybercrime group primarily involved in stealing payment card data by compromising PoS systems in retail and hospitality sectors. Their activities include targeting financial data for sale on dark web marketplaces, using techniques like phishing and malware deployment.

Goals & Targeting

FIN6's primary goal appears to be financial gain through the theft and sale of payment card data. They target sectors with high volumes of transactional data, such as retail and hospitality, due to the lucrative nature of this information. While their geographic focus is not explicitly detailed in all available sources, they are known to operate globally.

Enhanced Description

FIN6 has been actively involved in cyberattacks aimed at extracting sensitive payment card information from PoS systems within the hospitality and retail industries. They employ various tactics including spear-phishing attacks and deploying malicious software such as FrameworkPOS to infiltrate targeted systems. Their operations have resulted in significant data breaches, leading to financial losses and reputational damage for affected businesses. FIN6's activities are part of a broader trend of cybercriminal groups targeting the retail sector, where card data is highly valuable on the black market.

Key Capabilities

  • PoS malware deployment (e.g., FrameworkPOS)
  • Spear-phishing campaigns
  • Use of Cobalt Strike for attacks
  • Exfiltration of payment card data

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1053.005: Scheduled Task
T1566.003: Spearphishing via Service
T1204.002: Malicious File

Software / Tooling

FrameworkPOS
Cobalt Strike

Campaigns & Victims

FIN6's campaigns demonstrate a focus on long-term financial gain through data extraction. They have targeted PoS systems in multiple countries, though exact targets beyond sectors are not fully detailed here.

IOC Patterns

  • Spear-phishing via Service (T1566.003)
  • Distribution of malicious POS software
  • Scheduled Task creation to maintain persistence

Recommended Actions

  • Implement robust endpoint detection and response solutions.
  • Conduct regular employee training on phishing recognition.
  • Secure PoS systems with strong access controls.
  • Monitor networks for suspicious activities.

Suggested Tags

Cybercrime
Financial Fraud
PoS Malware

Confidence Assessment

High confidence in their primary activity and targets. Further details on specific targeting countries and campaigns would enhance this assessment.

ATT&CK Techniques

Collection
6 techniques
Credential Access
5 techniques
Execution
8 techniques
Stealth
5 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Crowdstrike Global Threat Report Feb 2018 — CrowdStrike. (2018, February 26). CrowdStrike 2018 Global Threat Report. Retrieved October 10, 2018.
  2. FireEye FIN6 April 2016 — FireEye Threat Intelligence. (2016, April). Follow the Money: Dissecting the Operations of the Cyber Crime Group FIN6. Retrieved November 17, 2024.
  3. FireEye FIN6 Apr 2019 — McKeague, B. et al. (2019, April 5). Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware. Retrieved April 17, 2019.
  4. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  5. Security Intelligence ITG08 April 2020 — Villadsen, O. (2020, April 7). ITG08 (aka FIN6) Partners With TrickBot Gang, Uses Anchor Framework. Retrieved October 8, 2020.
  6. Security Intelligence More Eggs Aug 2019 — Villadsen, O.. (2019, August 29). More_eggs, Anyone? Threat Actor ITG08 Strikes Again. Retrieved September 16, 2019.

Intel Summary

40

Techniques

11

Tools

0

Campaigns

4

IOCs

0

Observed Data

13

Tactics

Tags

APT
Financial Targeting
Healthcare Targeting
Cybercrime
Financial Fraud
PoS Malware

Details

MITRE ID
G0037
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--2a7914cf-dff3-428d-ab0f-1014d1c28aeb
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.