Also known as: Syssphinx, ATK113, G0061, PUNCH COMET
FIN8 is a financially motivated cyber threat group identified as early as January 2016. Initially known for targeting point-of-sale (POS) systems across various industries including hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. The group gained significant attention in June 2021 when researchers observed a shift in its tactics to distributing ransomware variants. This evolution highlights FIN8's adaptability and focus on maximizing financial gains through sophisticated cyberattacks. The group has been linked to several malware families and tools, including Sardonic, BADHATCH, Ragnar Locker, PUNCHBUGGY, and PUNCHTRACK, which are used to compromise systems, exfiltrate data, and deploy ransomware payloads. FIN8's operational persistence over multiple years underscores its capabilities and strategic targeting of high-value industries.
Targeted Sectors
Executive Summary
FIN8, also known as Syssphinx or G0061, is a financially motivated threat group primarily targeting sectors with high revenue potential such as hospitality, retail, and finance. Since at least 2016, FIN8 has shifted its tactics over time, initially focusing on compromising point-of-sale (POS) devices before evolving to distribute ransomware variants in recent years.
Goals & Targeting
FIN8's primary motivation is financial gain, achieved through the deployment of malware to steal sensitive information and disrupt business operations. The group strategically targets sectors with significant revenue potential, including hospitality, retail, technology, and finance, to maximize the impact of its campaigns.Typical victims include businesses with point-of-sale systems, financial institutions, and organizations with valuable intellectual property or customer data。
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
FIN8's campaigns demonstrate a focus on high-revenue industries and strategic use of malware for financial gain. The group has been observed compromising POS systems, stealing card data, and deploying ransomware to disrupt operations and demand payouts. Notable campaigns include the use of PUNCHBUGGY and PUNCHTRACK malware families for initial access and lateral movement within targeted networks. The shift in 2021 to distributing ransomware indicates a strategic evolution to capitalize on emerging opportunities in cyber extortion.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in FIN8's threat intelligence is moderately high, with substantial linked intelligence on its tools, techniques, and campaign patterns. However, gaps remain regarding the group's exact origin, initial access vectors, and long-term strategic objectives beyond financial gain. Limited reporting on specific APT-like campaigns further complicates comprehensive understanding of this active cyber threat.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
36
Techniques
8
Tools
0
Campaigns
0
IOCs
0
Observed Data
13
Tactics