FIN6
FIN is a group targeting financial assets including assets able to do financial transaction including PoS.
FIN6 is a financially motivated cybercrime group targeting PoS systems in retail and hospitality.
FIN6, also tracked as SKELETON SPIDER or ITG08, is a financially motivated group focused on stealing payment card data. They primarily target the retail and hospitality sectors, aiming to compromise Point of Sale (PoS) systems and related infrastructure. Their key TTPs include initial access via spearphishing (T1566), deploying Cobalt Strike for C2, using Mimikatz and PsExec for credential dumping and lateral movement, and collecting data from NTDS databases before exfiltration. Defenders should prioritize email security to block spearphishing, monitor for unauthorized use of remote execution tools like PsExec and RDP, and ensure strict network segmentation for PoS environments.
FIN is a group targeting financial assets including assets able to do financial transaction including PoS.
Monitor suspicious network activity to detect acquisition or development of tools.
Monitor suspicious email attachments and services to detect Spearphishing Attachment and Spearphishing via Service attacks.
Monitor command and script interpreters to detect suspicious Command and Scripting Interpreter activity.
Monitor Registry Run Keys and Startup Folder changes to detect suspicious persistence attempts.
Monitor Exploitation for Privilege Escalation activity to detect and remediate exploitation vulnerabilities.
Monitor command-line arguments to detect suspicious Command Obfuscation activity.
Monitor access to NTDS database to detect suspicious NTDS activity.
Monitor domain user account activity to detect Domain Account discovery.
Monitor RDP connections to detect suspicious Remote Desktop Protocol activity.
Monitor database and archiving activity to detect suspicious data collection.
Monitor network traffic to detect suspicious Protocol Tunneling activity.
Monitor non-C2 network traffic to detect suspicious Exfiltration Over Unencrypted Non-C2 Protocol activity.
Monitor security tools and code signing activity to detect suspicious Code Signing and Disable or Modify Tools activity.
FIN6 primarily uses spearphishing (T1566) for initial access.
FIN6 uses tools like PsExec for lateral movement and may also use RDP unauthorizedly.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.