FIN6
MITRE ATT&CK: G0037 View on attack.mitre.org
Aliases: Magecart Group 6, ITG08, Skeleton Spider, TAAL, Camouflage Tempest, SKELETON SPIDER, MageCart Group 6, White Giant, GOLD FRANKLIN, ATK88, TA4557, Storm-0538, FIN6
- First seen
- 2015-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Last IoC activity
- 2026-07-20 01:19:34
- Profile updated
- 2026-07-07 12:32:34
Targeted industries: retail-and-hospitality
Context
FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.
Detection coverage
- 163 YARA rules
- 837 Sigma rules
Malware & tools used
- Archive via Custom Method (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Domain Account (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Protocol Tunneling (attack-pattern)
- Databases (attack-pattern)
- Command Obfuscation (attack-pattern)
- JavaScript (attack-pattern)
- Web Service (attack-pattern)
- Data from Local System (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Windows Command Shell (attack-pattern)
- Tool (attack-pattern)
- File Deletion (attack-pattern)
- NTDS (attack-pattern)
- Access Token Manipulation (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Malicious File (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Spearphishing via Service (attack-pattern)
- PowerShell (attack-pattern)
- Archive Collected Data (attack-pattern)
- Code Signing (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- Mandiant — Rpt Fin6 (report)
- Mandiant — Pick Six Intercepting A Fin6 Intrusion (report)
- MITRE ATT&CK — G0037 (report)
- securityintelligence.com — More Eggs Anyone Threat Actor Itg08 Strikes Again (report)
- secureworks.com — Gold Franklin (report)
- CrowdStrike — 2019 Crowdstrike Global Threat Report (report)
- proofpoint.com — Security Brief Ta4557 Targets Recruiters Directly Email (report)
- proofpoint.com — Fake Jobs Campaigns Delivering Moreeggs Backdoor Fake Job Offers (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- crowdstrike.lookbookhq.com — Cs 2018 Global Threat Report (report)
- securityintelligence.com — Itg08 Aka Fin6 Partners With Trickbot Gang Uses Anchor Framework (report)
- web.archive.org — Rpt Fin6 (report)
External references
- mitre-attack — G0037
- Skeleton Spider
- FIN6
- TAAL
- Camouflage Tempest
- Magecart Group 6
- ITG08
- Crowdstrike Global Threat Report Feb 2018
- FireEye FIN6 April 2016
- FireEye FIN6 Apr 2019
- Microsoft Threat Actor Naming July 2023
- Security Intelligence ITG08 April 2020
- Security Intelligence More Eggs Aug 2019
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy