FIN4

MITRE ATT&CK: G0085 View on attack.mitre.org

Aliases: FIN4

First seen
2013-01-01 00:00:00
Origin
RO
Primary motivation
financial-gain
Sophistication
expert
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:50:33

Targeted industries: financial-services healthcare-and-pharmaceutical

Context

FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at least 2013. FIN4 is unique in that they do not infect victims with typical persistent malware, but rather they focus on capturing credentials authorized to access email and other non-public correspondence.

Detection coverage

  • 171 Sigma rules

Malware & tools used

  • Valid Accounts (attack-pattern)
  • Visual Basic (attack-pattern)
  • Multi-hop Proxy (attack-pattern)
  • Malicious File (attack-pattern)
  • Email Hiding Rules (attack-pattern)
  • Malicious Link (attack-pattern)
  • Keylogging (attack-pattern)
  • GUI Input Capture (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Web Protocols (attack-pattern)
  • Remote Email Collection (attack-pattern)

Reports & references

  • reuters.com — Us Hackers Insidertrading Iduskbn0P31M720150623 (report)
  • Mandiant — Fin4 Stealing Insid (report)
  • Mandiant — Rpt Fin4 (report)
  • pwc.blogs.com — Unfin4Ished Business (report)
  • MITRE ATT&CK — G0085 (report)
  • web.archive.org — Fin4 Stealing Insid (report)
  • Mandiant — Rpt Fin4 (report)
  • Mandiant — Wbnr 14Q4Namfin4 (report)

External references