FIN8
FIN8 is a financially motivated threat actor also tracked as Storm-0288 and Syssphinx. The provided content describes FIN8 as a financial threat actor associated with notably aggressive phishing campaigns. Observed tradecraft includes targeted spearphishing emails with malicious attachments, including Word documents with embedded macros, and malicious email attachments used to lure victims into executing malware. FIN8 has executed spearphishing payloads via PowerShell and used PowerShell scripts to determine host architecture before selecting a 32-bit or 64-bit .NET loader. The group has used WMI to launch malware and spawn cmd.exe, and has also used WMIC and the Impacket suite for lateral movement and post-compromise cleanup. Additional activity includes remote command execution via cmd.exe, use of batch files to automate cleanup, scheduled tasks to maintain RDP backdoors, use of Plink to tunnel RDP to command-and-control infrastructure, HTTPS for command and control, aggregation of staged data from victim networks into a single location, and post-compromise cleanup through deletion of tmp files, prefetch files, PowerShell scripts, and Registry keys.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
Associated vulnerabilities
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
FIN8 has exploited the CVE-2016-0167 local vulnerability.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
Observables
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in the detection annotations as a threat actor associated with exploitation for privilege escalation.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Referenced as a threat actor associated with registry modification behavior (MITRE ATT&CK T1112: Modify Registry) in the context of this detection analytic.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.