Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ FIN6

🌐FIN6

🌐 FIN6 is a tracked threat actor in the Clankerusecase corpus. Attributed to ??. Primary motivation: Criminal. We map 26 detection use cases to this actor across 62 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-24 to 2026-07-24.

crit 1
View full actor card → All threat actors MITRE ATT&CK group spec (G0037) ↗
26Use cases
1Articles
62Techniques
10IOCs

Known aliases

FIN6Skeleton SpiderCamouflage TempestITG08Magecart Group 6TAAL

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.003 · NTDST1005 · Data from Local SystemT1018 · Remote System DiscoveryT1021.002 · SMB/Windows Admin SharesT1027.010 · Command ObfuscationT1036.004 · Masquerade Task or ServiceT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1053.005 · Scheduled TaskT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1074.002 · Remote Data StagingT1078 · Valid AccountsT1087.002 · Domain AccountT1095 · Non-Application Layer ProtocolT1098.001 · Additional Cloud CredentialsT1102 · Web ServiceT1105 · Ingress Tool TransferT1110.002 · Password CrackingT1119 · Automated CollectionT1134 · Access Token ManipulationT1176 · Software ExtensionsT1185 · Browser Session HijackingT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1213.006 · DatabasesT1218 · System Binary Proxy ExecutionT1218.010 · Regsvr32T1486 · Data Encrypted for ImpactT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1547.001 · Registry Run Keys / Startup FolderT1553.002 · Code SigningT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1560 · Archive Collected DataT1560.003 · Archive via Custom MethodT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1566.003 · Spearphishing via ServiceT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.002 · Asymmetric CryptographyT1588.002 · ToolT1685 · Disable or Modify Tools

Detection use cases (26)

FIN6 / Skeleton Spider more_eggs loader: script-host spawning regsvr32/ie4uinit from a resume LNK AI · profile SΣDD FIN6 more_eggs C2: script-host LOLBins beaconing to the public internet AI · profile SDD TAG-195 ClickFix OCX payload executed via regsvr32 (TinyEgg install) Bespoke TAG-195 Golden Chickens C2 beacon to known staging/C2 infrastructure Bespoke ChromEggscalator: Chromium launched with --remote-debugging-port for cookie/credential theft Bespoke Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Suspicious browser extension installation Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal OAuth consent / suspicious app grant Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal 1Password impossible-travel sign-in MITRE match 1Password item exfiltration attempt MITRE match 1Password vault export attempted MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain MITRE match

Threat-intel articles (1)

Tracked indicators

Domains (6)

ahdaratlegalservices.com aurekh.com paysolutions.ink screenly.cam thessa.trackgrid.net xtrafftrck.net

IP addresses (4)

108.61.209.100 65.20.102.161 65.20.105.177 70.34.205.43