FIN5 is a financially motivated cybercrime group targeting restaurant, gaming, and hotel industries for payment card data.
Analyst brief
FIN5 (also tracked as G0053) is a financially motivated cybercrime group active since at least 2008, likely composed of Russian-speaking actors. It primarily targets the restaurant, gaming, and hotel industries to steal personally identifiable information (PII) and payment card data. Key TTPs include Credential Access via Brute Force, persistence through External Remote Services, deploying point-of-sale malware like RawPOS and FLIPSIDE, and anti-forensic measures such as File Deletion (SDelete) and clearing Windows Event Logs. Defenders should focus on enforcing strong password policies, monitoring for suspicious PsExec usage, and detecting the sudden clearing of Windows Event Logs on critical assets.
FIN5
G0053
unknown
FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian.