FIN8
MITRE ATT&CK: G0061 View on attack.mitre.org
Aliases: Syssphinx, ATK113, FIN8
- First seen
- 2016-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 7 (6 malicious)
- Last IoC activity
- 2026-04-17 13:41:22
- Profile updated
- 2026-07-07 12:31:52
Targeted industries: retail-and-hospitality media-and-entertainment financial-services technology-and-telecommunications
Context
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.
Recent IoC activity
6 malicious indicators in Maltiverse are attributed to FIN8 (G0061). The 6 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 307c3e23a4ba65749e49932c03d5d3eb58d133bc6623c436756e48de68b9cc45 | 2026-04-17 | 1 |
| file sample | 48e3add1881d60e0f6a036cfdb24426266f23f624a4cd57b8ea945e9ca98e6fd | 2026-03-26 | 1 |
| file sample | 1d3e573d432ef094fba33f615aa0564feffa99853af77e10367f54dc6df95509 | 2026-03-24 | 1 |
| file sample | 4db89c39db14f4d9f76d06c50fef2d9282e83c03e8c948a863b58dedc43edd31 | 2025-12-20 | 1 |
| file sample | e4e3a4f1c87ff79f99f42b5bbe9727481d43d68582799309785c95d1d0de789a | 2025-10-04 | 2 |
| file sample | 356adc348e9a28fc760e75029839da5d374d11db5e41a74147a263290ae77501 | 2025-09-30 | 1 |
Detection coverage
- 5 YARA rules
- 910 Sigma rules
Malware & tools used
- Valid Accounts (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- LSASS Memory (attack-pattern)
- Tool (attack-pattern)
- Malicious File (attack-pattern)
- Code Signing Certificates (attack-pattern)
- Exploitation for Privilege Escalation (attack-pattern)
- Windows Management Instrumentation Event Subscription (attack-pattern)
- Spearphishing Link (attack-pattern)
- Scheduled Task (attack-pattern)
- Malicious Link (attack-pattern)
- Web Service (attack-pattern)
- Command Obfuscation (attack-pattern)
- File Deletion (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Web Protocols (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Archive via Utility (attack-pattern)
- Remote Data Staging (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
Reports & references
- cloud.google.com — Updated Cyber Threat Actor Naming System (report)
- Mandiant — Windows Zero Day Payment Cards (report)
- Mandiant — Wbnr Know Your Enemy Unc622 Spear Phishing (report)
- root9b.com — Pos%20Malware%20Shelltea%20Poslurp (report)
- afyonluoglu.org — 2017%20Fireeye%20M Trends%20Report (report)
- Mandiant — Obfuscation In The Wild (report)
- MITRE ATT&CK — G0061 (report)
- Broadcom/Symantec — Syssphinx Fin8 Backdoor (report)
- web.archive.org — Obfuscation In The Wild (report)
- bitdefender.com — Bitdefender Pr Whitepaper Fin8 Creat5619 En En (report)