🌐FIN6
🌐 FIN6 is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: Criminal. We map 14 detection use cases to this actor across 40 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
40Techniques
0IOCs
About this actor (MITRE)
[FIN6](https://attack.mitre.org/groups/G0037) is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.(Citation: FireEye FIN6 April 2016)(Citation: FireEye FIN6 Apr 2019)
Known aliases
FIN6Magecart Group 6ITG08Skeleton SpiderTAALCamouflage Tempest
All other tracked techniques
T1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1027.010 · Command ObfuscationT1036.004 · Masquerade Task or ServiceT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1053.005 · Scheduled TaskT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1074.002 · Remote Data StagingT1078 · Valid AccountsT1087.002 · Domain AccountT1095 · Non-Application Layer ProtocolT1102 · Web ServiceT1110.002 · Password CrackingT1119 · Automated CollectionT1134 · Access Token ManipulationT1204.002 · Malicious FileT1213.006 · DatabasesT1547.001 · Registry Run Keys / Startup FolderT1553.002 · Code SigningT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1560 · Archive Collected DataT1560.003 · Archive via Custom MethodT1566.001 · Spearphishing AttachmentT1566.003 · Spearphishing via ServiceT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1573.002 · Asymmetric CryptographyT1588.002 · ToolT1685 · Disable or Modify Tools