FIN4
MITRE ATT&CK: G0085 View on attack.mitre.org
Aliases: FIN4
- First seen
- 2013-01-01 00:00:00
- Origin
- RO
- Primary motivation
- financial-gain
- Sophistication
- expert
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:50:33
Targeted industries: financial-services healthcare-and-pharmaceutical
Context
FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at least 2013. FIN4 is unique in that they do not infect victims with typical persistent malware, but rather they focus on capturing credentials authorized to access email and other non-public correspondence.
Detection coverage
- 171 Sigma rules
Malware & tools used
- Valid Accounts (attack-pattern)
- Visual Basic (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Malicious File (attack-pattern)
- Email Hiding Rules (attack-pattern)
- Malicious Link (attack-pattern)
- Keylogging (attack-pattern)
- GUI Input Capture (attack-pattern)
- Spearphishing Link (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Web Protocols (attack-pattern)
- Remote Email Collection (attack-pattern)
Reports & references
- reuters.com — Us Hackers Insidertrading Iduskbn0P31M720150623 (report)
- Mandiant — Fin4 Stealing Insid (report)
- Mandiant — Rpt Fin4 (report)
- pwc.blogs.com — Unfin4Ished Business (report)
- MITRE ATT&CK — G0085 (report)
- web.archive.org — Fin4 Stealing Insid (report)
- Mandiant — Rpt Fin4 (report)
- Mandiant — Wbnr 14Q4Namfin4 (report)