FIN5

MITRE ATT&CK: G0053 View on attack.mitre.org

Aliases: FIN5

First seen
2008-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:57:01

Targeted industries: retail-and-hospitality

Context

FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian.

Detection coverage

  • 2 YARA rules
  • 227 Sigma rules

Malware & tools used

  • External Proxy (attack-pattern)
  • File Deletion (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Automated Collection (attack-pattern)
  • Brute Force (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Tool (attack-pattern)
  • External Remote Services (attack-pattern)
  • Valid Accounts (attack-pattern)
  • FLIPSIDE (malware)
  • Windows Credential Editor (malware)
  • RawPOS (malware)
  • pwdump (malware)
  • SDelete (malware)
  • PsExec (malware)

Reports & references

  • darkreading.com — 1322645 (report)
  • MITRE ATT&CK — G0053 (report)
  • youtube.com — Watch (report)
  • Mandiant — Wbnr Are You Ready To Respond (report)

External references