G0061: FIN8
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.[1][2][3][4]
Security context for executives and security teams
G0061: FIN8 describes [FIN8](https://attack.mitre.org/groups/G0061) is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected [FIN8](https://attack.mitre.org/groups/G0061) switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.(Citation: FireEye Obfuscation June 2017)(Citation: Fire...
Executive priority
G0061: FIN8 is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0061: FIN8 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0061: FIN8 appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
FIN8
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.[1][2][3][4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1078 | Valid Accounts | FIN8 has used valid accounts for persistence and lateral movement.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1048.003 | Exfiltration Over Unencrypted Non-C2 ProtocolSub-technique | FIN8 has used FTP to exfiltrate collected data.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1033 | System Owner/User Discovery | |
| Enterprise | T1518.001 | Security Software DiscoverySub-technique | FIN8 has used Registry keys to detect and avoid executing in potential sandboxes.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | FIN8 has used RDP for lateral movement.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1003.001 | LSASS MemorySub-technique | FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE).CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1588.002 | ToolSub-technique | |
| Enterprise | T1204.002 | Malicious FileSub-technique | |
| Enterprise | T1588.003 | Code Signing CertificatesSub-technique | |
| Enterprise | T1068 | Exploitation for Privilege Escalation | |
| Enterprise | T1546.003 | Windows Management Instrumentation Event SubscriptionSub-technique | FIN8 has used WMI event subscriptions for persistence.CitationBitdefender FIN8 July 2021 |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | FIN8 has distributed targeted emails containing links to malicious documents with embedded macros.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | FIN8 has used scheduled tasks to maintain RDP backdoors.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1204.001 | Malicious LinkSub-technique | |
| Enterprise | T1102 | Web Service | FIN8 has used |
| Enterprise | T1027.010 | Command ObfuscationSub-technique | |
| Enterprise | T1070.004 | File DeletionSub-technique | |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | FIN8 has used HTTPS for command and control.CitationBitdefender FIN8 July 2021 |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | |
| Enterprise | T1685.005 | Clear Windows Event LogsSub-technique | FIN8 has cleared logs during post compromise cleanup activities.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | FIN8 has used RAR to compress collected data before exfiltration.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1074.002 | Remote Data StagingSub-technique | FIN8 aggregates staged data from a network into a single location.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1105 | Ingress Tool Transfer | |
| Enterprise | T1082 | System Information Discovery | |
| Enterprise | T1059.001 | PowerShellSub-technique | FIN8's malicious spearphishing payloads are executed as PowerShell. FIN8 has also used PowerShell for lateral movement and credential access.[1]CitationBitdefender FIN8 July 2021CitationFireEye Know Your Enemy FIN8 Aug 2016[4] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | |
| Enterprise | T1573.002 | Asymmetric CryptographySub-technique | FIN8 has used the Plink utility to tunnel RDP back to C2 infrastructure.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1055.004 | Asynchronous Procedure CallSub-technique | FIN8 has injected malicious code into a new svchost.exe process.CitationBitdefender FIN8 July 2021 |
| Enterprise | T1018 | Remote System Discovery | |
| Enterprise | T1486 | Data Encrypted for Impact | FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.[4] |
| Enterprise | T1482 | Domain Trust Discovery | FIN8 has retrieved a list of trusted domains by using |
| Enterprise | T1112 | Modify Registry | FIN8 has deleted Registry keys during post compromise cleanup activities.CitationFireEye Know Your Enemy FIN8 Aug 2016 |
| Enterprise | T1134.001 | Token Impersonation/TheftSub-technique | |
| Enterprise | T1016.001 | Internet Connection DiscoverySub-technique | |
| Enterprise | T1047 | Windows Management Instrumentation | FIN8's malicious spearphishing payloads use WMI to launch malware and spawn `cmd.exe` execution. FIN8 has also used WMIC and the Impacket suite for lateral movement, as well as during and post compromise cleanup activities.[1]CitationBitdefender FIN8 July 2021CitationFireEye Know Your Enemy FIN8 Aug 2016[4] |
Groups, software, and campaigns
S0097: Ping
S1081: BADHATCH
S0196: PUNCHBUGGY
PUNCHBUGGY is a backdoor malware used by FIN8 that has been observed targeting POS networks in the hospitality industry. [1][2] [3]
S0481: Ragnar Locker
Ragnar Locker is a ransomware that has been in use since at least December 2019.[1][2]
S0197: PUNCHTRACK
PUNCHTRACK is non-persistent point of sale (POS) system malware utilized by FIN8 to scrape payment card data. [1] [2]
S0105: dsquery
dsquery is a command-line utility that can be used to query Active Directory for information from a system within a domain. [1] It is typically installed only on Windows Server versions but can be installed on non-server variants through the Microsoft-provided Remote Server Administration Tools bundle.
S0039: Net
The Net utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. [1]
Net has a great deal of functionality, [2] much of which is useful for an adversary, such as gathering system and network information for Discovery, moving laterally through SMB/Windows Admin Shares using net use commands, and interacting with services. The net1.exe utility is executed for certain functionality when net.exe is run and can be used directly in commands such as net1 user.
S0359: Nltest
S1085: Sardonic
S0029: PsExec
S0357: Impacket
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.0 | Current bundle | 4cb9130a1b74… | ||
| 19.1 | 2.0 | Older bundle | bb5a34d483ce… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]FireEye Obfuscation June 2017
Bohannon, D. & Carr N. (2017, June 30). Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques. Retrieved February 12, 2018.
Open source URL - [2]FireEye Fin8 May 2016
Kizhakkinan, D., et al. (2016, May 11). Threat Actor Leverages Windows Zero-day Exploit in Payment Card Data Attacks. Retrieved February 12, 2018.
Open source URL - [3]Bitdefender Sardonic Aug 2021
Budaca, E., et al. (2021, August 25). FIN8 Threat Actor Goes Agile with New Sardonic Backdoor. Retrieved August 9, 2023.
Open source URL - [4]Symantec FIN8 Jul 2023
Symantec Threat Hunter Team. (2023, July 18). FIN8 Uses Revamped Sardonic Backdoor to Deliver Noberus Ransomware. Retrieved August 9, 2023.
Open source URL - [5]FIN8
(Citation: FireEye Obfuscation June 2017)
- [6]Syssphinx
(Citation: Symantec FIN8 Jul 2023)
- [7]mitre-attackG0061Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
