LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0061: FIN8

FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.CitationFireEye Obfuscation June 2017CitationFireEye Fin8 May 2016CitationBitdefender Sardonic Aug 2021CitationSymantec FIN8 Jul 2023

EnterpriseG0061GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

FIN8 is a financially motivated ATT&CK group associated with payment-card/POS activity and, per cited research, later distribution of ransomware variants. For leaders, the value of this object is less about a single indicator and more about validating whether the organization can detect and respond to a Windows-heavy intrusion path involving discovery, credential access, lateral movement, remote administration tools, backdoors, possible data theft, and ransomware-related activity.

Executive priority

Prioritize FIN8 as a resilience and payment/data-risk planning scenario for sectors named by ATT&CK: hospitality, retail, entertainment, insurance, technology, chemical, and financial organizations. Useful executive questions include: are POS and business Windows environments segmented; can the SOC see credential theft against LSASS, RDP/SMB lateral movement, WMI, PowerShell, scheduled tasks, and admin-tool abuse; and is incident response prepared for both payment-data theft and ransomware decision points? This object supports budget and audit discussions around identity controls, endpoint visibility, network segmentation, logging retention, and ransomware readiness, but it does not by itself prove exposure or current targeting of any specific organization.

Technical view

ATT&CK provides no group-level detection text and no group-level platform list, so defenders should anchor validation to the related software and techniques. FIN8 is related to Windows-oriented tools and behaviors including PsExec, Net, dsquery, Nltest, WMI, PowerShell, Windows Command Shell, scheduled tasks, RDP, SMB/admin shares, LSASS memory access, command obfuscation, APC injection, and backdoors such as PUNCHBUGGY, BADHATCH, and Sardonic. It is also related to PUNCHTRACK POS malware and Ragnar Locker ransomware. SOC and IR teams should test whether they can reconstruct an intrusion timeline across endpoint process activity, authentication, domain enumeration, lateral movement, persistence, exfiltration, and malware execution without relying on a single signature.

Likely telemetry

  • Endpoint process creation and command-line logging for PowerShell, cmd, PsExec, Net, dsquery, Nltest, WMI, scheduled task creation, and unusual administrative execution
  • Windows security logs and identity telemetry for logons, privileged account use, RDP sessions, SMB/admin share access, and domain enumeration patterns
  • Endpoint detection telemetry for LSASS memory access, process injection/APC-style behavior, suspicious DLL/plugin loading, and backdoor execution indicators
  • Network telemetry for internal discovery, ping/network probing, SMB/RDP movement, and outbound transfers over unencrypted non-C2 protocols such as HTTP, FTP, or DNS where applicable
  • POS environment telemetry where POS networks exist, including host integrity, process execution, network segmentation evidence, and payment-system access patterns

Detection direction

  • Because no official detection guidance is supplied for FIN8, validate detections against the related ATT&CK techniques rather than the group name alone.
  • Tune for suspicious combinations: domain discovery with dsquery/Nltest/Net, followed by RDP/SMB or PsExec/WMI activity, followed by credential access or scheduled task creation.
  • Treat legitimate administration tools as dual-use. Reduce false positives by baselining approved administrator hosts, service accounts, maintenance windows, and normal command-line patterns.
  • Confirm visibility into command obfuscation for PowerShell and Windows Command Shell; simple string matching may miss altered or encoded commands.
  • Validate controls for LSASS access and credential dumping attempts, especially where administrative privileges are common or poorly separated.

Mitigation priorities

  • Start with identity hardening: least privilege, separation of administrative accounts, strong authentication for remote access, and review of privileged service account use.
  • Restrict and monitor lateral movement paths, especially RDP, SMB/admin shares, PsExec-style execution, and WMI remote execution.
  • Harden Windows endpoints against credential theft and script abuse, including tighter PowerShell controls, command-line logging, and protection of LSASS where supported by the environment.
  • Segment POS and other critical business systems from general user networks, and ensure monitoring spans both sides of segmentation boundaries.
  • Control scheduled task creation and remote administration tooling through policy, change control, and alerting rather than assuming all use is benign.
Additional notes and limits

The ATT&CK object identifies FIN8 aliases as FIN8 and Syssphinx and describes activity since at least January 2016, sectors historically targeted, a shift reported in June 2021 from POS targeting to ransomware variant distribution, and relationships to multiple tools, malware families, and techniques. The practical defensive takeaway is to use FIN8 as an emulation and coverage-review scenario spanning POS risk, Windows enterprise intrusion tradecraft, identity compromise, and ransomware readiness.

ATT&CK supplies no official detection text, no group-level platforms, and no environment-specific indicators in the provided fields. The related techniques and software support defensive validation themes, but local telemetry, asset inventory, sector exposure, POS presence, identity architecture, and incident history are required to determine actual risk and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

FIN8

FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.CitationFireEye Obfuscation June 2017CitationFireEye Fin8 May 2016CitationBitdefender Sardonic Aug 2021CitationSymantec FIN8 Jul 2023

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
bb5a34d483ce5437...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.