FIN5
MITRE ATT&CK: G0053 View on attack.mitre.org
Aliases: FIN5
- First seen
- 2008-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:57:01
Targeted industries: retail-and-hospitality
Context
FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian.
Detection coverage
- 2 YARA rules
- 227 Sigma rules
Malware & tools used
- External Proxy (attack-pattern)
- File Deletion (attack-pattern)
- Local Data Staging (attack-pattern)
- Command and Scripting Interpreter (attack-pattern)
- Remote System Discovery (attack-pattern)
- Automated Collection (attack-pattern)
- Brute Force (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Tool (attack-pattern)
- External Remote Services (attack-pattern)
- Valid Accounts (attack-pattern)
- FLIPSIDE (malware)
- Windows Credential Editor (malware)
- RawPOS (malware)
- pwdump (malware)
- SDelete (malware)
- PsExec (malware)
Reports & references
- darkreading.com — 1322645 (report)
- MITRE ATT&CK — G0053 (report)
- youtube.com — Watch (report)
- Mandiant — Wbnr Are You Ready To Respond (report)