FIN6

MITRE ATT&CK: G0037 View on attack.mitre.org

Aliases: Magecart Group 6, ITG08, Skeleton Spider, TAAL, Camouflage Tempest, SKELETON SPIDER, MageCart Group 6, White Giant, GOLD FRANKLIN, ATK88, TA4557, Storm-0538, FIN6

First seen
2015-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Last IoC activity
2026-07-20 01:19:34
Profile updated
2026-07-07 12:32:34

Targeted industries: retail-and-hospitality

Context

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.

Detection coverage

  • 163 YARA rules
  • 837 Sigma rules

Malware & tools used

  • Archive via Custom Method (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Domain Account (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Protocol Tunneling (attack-pattern)
  • Databases (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • JavaScript (attack-pattern)
  • Web Service (attack-pattern)
  • Data from Local System (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Tool (attack-pattern)
  • File Deletion (attack-pattern)
  • NTDS (attack-pattern)
  • Access Token Manipulation (attack-pattern)
  • Exploitation for Privilege Escalation (attack-pattern)
  • Malicious File (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Spearphishing via Service (attack-pattern)
  • PowerShell (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Code Signing (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • Mandiant — Rpt Fin6 (report)
  • Mandiant — Pick Six Intercepting A Fin6 Intrusion (report)
  • MITRE ATT&CK — G0037 (report)
  • securityintelligence.com — More Eggs Anyone Threat Actor Itg08 Strikes Again (report)
  • secureworks.com — Gold Franklin (report)
  • CrowdStrike — 2019 Crowdstrike Global Threat Report (report)
  • proofpoint.com — Security Brief Ta4557 Targets Recruiters Directly Email (report)
  • proofpoint.com — Fake Jobs Campaigns Delivering Moreeggs Backdoor Fake Job Offers (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • crowdstrike.lookbookhq.com — Cs 2018 Global Threat Report (report)
  • securityintelligence.com — Itg08 Aka Fin6 Partners With Trickbot Gang Uses Anchor Framework (report)
  • web.archive.org — Rpt Fin6 (report)

External references