LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0053: FIN5

FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian. [1] [2] [3]

EnterpriseG0053GroupObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

FIN5 matters because ATT&CK describes it as a financially motivated group associated with targeting personally identifiable information and payment card information, especially in restaurant, gaming, and hotel environments. For leaders, the key issue is not just malware: the relationship set points to credential abuse, remote access, lateral movement, collection, log clearing, and POS-focused malware, which can turn weak identity controls and poor endpoint visibility into cardholder-data and privacy risk.

Executive priority

Prioritize validation around environments that store, process, or can reach payment card or PII data. Ask whether remote access, privileged account use, Windows administrative tools, POS systems, and event-log retention are governed well enough to support incident response and audit evidence. Because ATT&CK provides no official detection guidance for this group, coverage should be proven through local telemetry tests and control reviews rather than assumed from tool ownership.

Technical view

The supplied relationships emphasize credential dumping tools such as Windows Credential Editor and pwdump, valid account abuse, brute force, external remote services, PsExec-style remote execution, remote system discovery, command/script execution, local data staging, automated collection, external proxying, file deletion, Windows event-log clearing, and RawPOS/FLIPSIDE usage. SOC and IR teams should validate visibility across authentication, endpoint process execution, remote service access, administrative lateral movement, POS/cardholder-data environments, data staging, and log-tampering signals. Treat PsExec and Sysinternals utilities carefully because they can be legitimate administrative tools as well as attacker-used tools.

Likely telemetry

  • Authentication logs for VPN, remote access services, identity providers, privileged accounts, failed login patterns, and anomalous successful logins
  • Endpoint process creation and command-line telemetry, especially for scripting interpreters, credential dumping tools, PsExec-like execution, and Sysinternals utilities
  • Windows Security, System, and Application event logs, including evidence of log clearing or gaps in expected logging
  • Network telemetry for remote service access, internal discovery, lateral movement, and proxy-like outbound connections
  • File system telemetry for local staging directories, unusual file creation/copying, deletion activity, and secure-delete utility use

Detection direction

  • Start with identity-centric detections: unusual valid-account use, brute-force patterns, remote-service access from unexpected sources, and privileged account activity outside normal administration.
  • Tune lateral-movement analytics around PsExec-like behavior and remote execution, but account for legitimate IT administration to reduce false positives.
  • Validate endpoint rules for credential dumping tools and suspicious command/script interpreter use; do not rely only on file names because tools can be renamed.
  • Monitor for discovery followed by staging, collection, or outbound proxy-like traffic, as the relationships span discovery, collection, and command-and-control behaviors.
  • Create high-priority alerts for Windows event-log clearing or unexplained log gaps, especially on systems that access payment card or PII data.

Mitigation priorities

  • Harden identity first: enforce strong authentication for external remote services, reduce standing privilege, review service accounts, and monitor privileged access paths.
  • Restrict and monitor administrative remote execution tools; allow known-good administration patterns while alerting on unusual hosts, users, or execution contexts.
  • Protect credential material on Windows systems and prioritize controls that reduce credential dumping and reuse opportunities.
  • Segment POS and cardholder-data environments from general enterprise systems and limit which accounts and hosts can reach them.
  • Preserve incident evidence by centralizing logs, protecting log stores from local administrator tampering, and testing retention during IR exercises.
Additional notes and limits

This take is based on the official FIN5 ATT&CK group description and supplied relationships. The object itself lists no platforms or tactics and provides no official detection text, so the technical framing is derived from related software and techniques rather than a complete ATT&CK procedure narrative.

Local exposure depends on whether the organization operates relevant payment card, PII, POS, hospitality, gaming, or restaurant environments and whether the referenced behaviors are observable in existing telemetry. The supplied data does not establish current activity, victim exposure, guaranteed detection logic, or complete platform scope for the group.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

FIN5

FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the restaurant, gaming, and hotel industries. The group is made up of actors who likely speak Russian. [1] [2] [3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

11 rows
DomainIDNameRelationship / procedure
EnterpriseT1090.002External ProxySub-technique

FIN5 maintains access to victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel.[2]

EnterpriseT1070.004File DeletionSub-technique

FIN5 uses SDelete to clean up the environment and attempt to prevent detection.[2]

EnterpriseT1074.001Local Data StagingSub-technique

FIN5 scripts save memory dump data into a specific directory on hosts in the victim environment.[2]

EnterpriseT1059Command and Scripting Interpreter

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.[2]

EnterpriseT1018Remote System Discovery

FIN5 has used the open source tool Essential NetTools to map the network and build a list of targets.[2]

EnterpriseT1119Automated Collection

FIN5 scans processes on all victim systems in the environment and uses automated scripts to pull back the results.[2]

EnterpriseT1110Brute Force

FIN5 has has used the tool GET2 Penetrator to look for remote login and hard-coded credentials.[3][2]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

FIN5 has cleared event logs from victims.[2]

EnterpriseT1588.002ToolSub-technique

FIN5 has obtained and used a customized version of PsExec, as well as use other tools such as pwdump, SDelete, and Windows Credential Editor.[2]

EnterpriseT1133External Remote Services

FIN5 has used legitimate VPN, Citrix, or VNC credentials to maintain access to a victim environment.[1][3][2]

EnterpriseT1078Valid Accounts

FIN5 has used legitimate VPN, RDP, Citrix, or VNC credentials to maintain access to a victim environment.[1][3][2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0195: SDelete

SDelete is an application that securely deletes data in a way that makes it unrecoverable. It is part of the Microsoft Sysinternals suite of tools. [1]

Windows
MalwareEnterprise

S0169: RawPOS

RawPOS is a point-of-sale (POS) malware family that searches for cardholder data on victims. It has been in use since at least 2008. [1] [2] [3] FireEye divides RawPOS into three components: FIENDCRY, DUEBREW, and DRIFTWOOD. [4] [5]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
7549f0864252fadd...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle7549f0864252…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    FireEye Respond Webinar July 2017

    Scavella, T. and Rifki, A. (2017, July 20). Are you Ready to Respond? (Webinar). Retrieved October 4, 2017.

    Open source URL
  2. [2]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  3. [3]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  4. [4]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  5. [5]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  6. [6]
    FIN5

    (Citation: FireEye Respond Webinar July 2017) (Citation: Mandiant FIN5 GrrCON Oct 2016) (Citation: DarkReading FireEye FIN5 Oct 2015)

  7. [7]
    FIN5

    (Citation: FireEye Respond Webinar July 2017) (Citation: Mandiant FIN5 GrrCON Oct 2016) (Citation: DarkReading FireEye FIN5 Oct 2015)

  8. [8]
    FIN5

    (Citation: FireEye Respond Webinar July 2017) (Citation: Mandiant FIN5 GrrCON Oct 2016) (Citation: DarkReading FireEye FIN5 Oct 2015)

  9. [9]
    FireEye Respond Webinar July 2017

    Scavella, T. and Rifki, A. (2017, July 20). Are you Ready to Respond? (Webinar). Retrieved October 4, 2017.

    Open source URL
  10. [10]
    FireEye Respond Webinar July 2017

    Scavella, T. and Rifki, A. (2017, July 20). Are you Ready to Respond? (Webinar). Retrieved October 4, 2017.

    Open source URL
  11. [11]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  12. [12]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  13. [13]
    mitre-attackG0053
    Open source URL
  14. [14]
    mitre-attackG0053
    Open source URL
  15. [15]
    mitre-attackG0053
    Open source URL
  16. [16]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  17. [17]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  18. [18]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  19. [19]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  20. [20]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  21. [21]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  22. [22]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  23. [23]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  24. [24]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  25. [25]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  26. [26]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  27. [27]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  28. [28]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  29. [29]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  30. [30]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  31. [31]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  32. [32]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  33. [33]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  34. [34]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  35. [35]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  36. [36]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  37. [37]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  38. [38]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  39. [39]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  40. [40]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  41. [41]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  42. [42]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  43. [43]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  44. [44]
    FireEye Respond Webinar July 2017

    Scavella, T. and Rifki, A. (2017, July 20). Are you Ready to Respond? (Webinar). Retrieved October 4, 2017.

    Open source URL
  45. [45]
    FireEye Respond Webinar July 2017

    Scavella, T. and Rifki, A. (2017, July 20). Are you Ready to Respond? (Webinar). Retrieved October 4, 2017.

    Open source URL
  46. [46]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  47. [47]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  48. [48]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  49. [49]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  50. [50]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  51. [51]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  52. [52]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  53. [53]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  54. [54]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  55. [55]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
  56. [56]
    DarkReading FireEye FIN5 Oct 2015

    Higgins, K. (2015, October 13). Prolific Cybercrime Gang Favors Legit Login Credentials. Retrieved October 4, 2017.

    Open source URL
  57. [57]
    FireEye Respond Webinar July 2017

    Scavella, T. and Rifki, A. (2017, July 20). Are you Ready to Respond? (Webinar). Retrieved October 4, 2017.

    Open source URL
  58. [58]
    Mandiant FIN5 GrrCON Oct 2016

    Bromiley, M. and Lewis, P. (2016, October 7). Attacking the Hospitality and Gaming Industries: Tracking an Attacker Around the World in 7 Years. Retrieved October 6, 2017.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.