FIN1 is a cybercriminal group targeting the financial industry with 'Nemesis' malware to steal cardholder data.
Analyst brief
FIN1 is a financially motivated cybercriminal group, likely located in Russia or a Russian-speaking country. The group primarily targets the financial industry to steal easily monetizable cardholder data. Their key TTPs involve deploying a custom malware ecosystem called 'Nemesis' to gain access and exfiltrate sensitive information. Defenders should focus on detecting anomalous file and utility executions, particularly access attempts targeting financial data repositories.
FIN1
unknown
FireEye first identified this activity during a recent investigation at an organization in the financial industry. They identified the presence of a financially motivated threat group that they track as FIN1, whose activity at the organization dated back several years. The threat group deployed numerous malicious files and utilities, all of which were part of a malware ecosystem referred to as ‘Nemesis’ by the malware developer(s), and used this malware to access the victim environment and steal cardholder data. FIN1, which may be located in Russia or a Russian-speaking country based on language settings in many of their custom tools, is known for stealing data that is easily monetized from financial services organizations such as banks, credit unions, ATM operations, and financial transaction processing and financial business services companies.