FIN8
FIN8 is a financially motivated group targeting the retail, hospitality and entertainment industries. The actor had previously conducted several tailored spearphishing campaigns using the downloader PUNCHBUGGY and POS malware PUNCHTRACK.
FIN8 is a financially motivated cybercriminal group targeting retail, hospitality, and entertainment sectors.
FIN8 (also tracked as Syssphinx) is a financially motivated cybercriminal group targeting the retail, hospitality, and entertainment sectors. They typically gain initial access via tailored spearphishing links, then steal credentials from LSASS memory and move laterally using RDP and SMB/Windows Admin Shares. The group leverages custom malware like BADHATCH and PUNCHBUGGY, along with tools such as PsExec and Impacket, often exfiltrating archived data over unencrypted non-C2 protocols. Defenders should focus on detecting spearphishing emails, unusual RDP traffic, LSASS access attempts, and the clearing of Windows Event Logs.
FIN8 is a financially motivated group targeting the retail, hospitality and entertainment industries. The actor had previously conducted several tailored spearphishing campaigns using the downloader PUNCHBUGGY and POS malware PUNCHTRACK.
Monitor suspicious network activity to detect acquisition of malicious tools.
Monitor Spearphishing Link activity to detect suspicious email links.
Monitor Malicious File activity to detect execution of suspicious files.
Monitor Exploitation for Privilege Escalation activity to detect attempts to escalate privileges.
Monitor Command Obfuscation and Valid Accounts activity to detect suspicious commands and valid accounts.
Monitor LSASS Memory activity to detect attempts to steal credentials from LSASS memory.
Monitor System Owner/User Discovery and Security Software Discovery activity to detect discovery of system owner/user information and security software.
Monitor Remote Desktop Protocol and SMB/Windows Admin Shares activity to detect suspicious remote desktop and SMB activity.
Monitor Archive via Utility activity to detect attempts to archive data.
Monitor Web Service activity to detect suspicious web service activity.
Monitor Exfiltration Over Unencrypted Non-C2 Protocol activity to detect attempts to exfiltrate data over unencrypted non-C2 protocol.
Monitor Clear Windows Event Logs activity to detect attempts to clear Windows event logs.
Monitor Data Encrypted for Impact activity to detect attempts to encrypt data for impact.
They use tailored spearphishing links for initial access.
They steal credentials from LSASS memory.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.