National Cyber Warfare Foundation (NCWF)

FIN6


0 user ratings
2024-06-18 15:21:26
blscott

 - archive -- 

FIN6

MITRE:  G0037

FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.

 Alternate names
Magecart Group 6, ITG08, Skeleton Spider, TAAL, Camouflage TempestATK
88, ATK88, Camouflage Tempest, FIN6, G0037, GOLD FRANKLIN, ITG08, MageCart
Group 6, SKELETON SPIDER, TA4557, TAAL, TAG-CR2, White Giant,


FIN6 is an advanced persistent threat (APT) that has been active since at least 2013 and continues to target financial institutions, government agencies, and other organizations worldwide. It uses a variety of tactics such as spear-phishing emails, malware injections, and social engineering techniques to gain access to sensitive information and steal money from victims\' accounts. FIN6 is also known for its sophisticated infrastructure that includes multiple command and control servers located around the world, making it difficult to track down and stop. The group has been linked to several high-profile attacks in recent years, including the 2018 cyberattack on Russian bank Sberbank.

Techniques, tactics and practices:

FIN6 uses a variety of tactics such as spear-phishing emails, malware injections, and social engineering techniques to gain access to sensitive information. They also use sophisticated infrastructure that includes multiple command and control servers located around the world, making it difficult to track down and stop them. Additionally, they have been known to target financial institutions, government agencies, and other organizations worldwide in order to steal money from victims\' accounts.

FIN is a group targeting financial
assets including assets able to do financial transaction including PoS. FIN6 is
a cybercrime group that has stolen payment card data and sold it for profit on
underground marketplaces. This group has aggressively targeted and compromised
point of sale (PoS) systems in the hospitality and retail sectors. (FireEye)
FIN6 is a cybercriminal group intent on stealing payment card data for
monetization. In 2015, FireEye Threat Intelligence supported several Mandiant
Consulting investigations in the hospitality and retail sectors where FIN6
actors had aggressively targeted and compromised point-of-sale (POS) systems,
making off with millions of payment card numbers. Through iSIGHT, we learned
that the payment card numbers stolen by FIN6 were sold on a “card shop” — an
underground criminal marketplace used to sell or exchange payment card data.

 First seen

2015

 Target categories

Chemical, Energy, Hospitality, Manufacturing, Retail,

Tools

AbaddonPOS (category:
Malware)


type: POS malware

(Proofpoint) Proofpoint threat researchers recently detected a new addition to
PoS malware landscape. Named AbaddonPOS by Proofpoint researchers, this sample
was initially discovered as it was being downloaded in the process of a
\'Vawtrak\' infection. This use of additional payloads to enhance attack
capabilities offers another example of efforts by threat actors to expand their
target surfaces through the delivery of multiple payloads in a single campaign,
in this case by including potential PoS terminals. This post will analyze
AbaddonPOS; discuss the observed infection vectors; and expose, details on the
downloader used to retrieve this new PoS malware. We will also provide evidence
to demonstrate that the downloader malware and PoS malware are closely related,
perhaps even written by the same actor or actors.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=1e27e4a7-2583-4e55-9fe3-ffee54333563

https://www.proofpoint.com/us/threat-insight/post/AbaddonPOS-A-New-Point-Of-Sale-Threat-Linked-To-Vawtrak

https://threatpost.com/new-pos-malware-pinkkite-takes-flight/130428/

https://www.proofpoint.com/us/threat-insight/post/abaddonpos-now-targeting-specific-pos-software

https://malpedia.caad.fkie.fraunhofer.de/details/win.abaddon_pos

https://otx.alienvault.com/browse/pulses?q=tag:abaddonpos



Anchor (category:
Malware)


type: Backdoor

(Cybereason) During our investigation, we found several unidentified malware
samples related to \'TrickBot\' infections. The malware is dubbed Anchor by its
authors and has been active since August 2018. Unlike Anchor_DNS, the Anchor
malware does not implement communication over DNS. However, it does share many
behavioral, code, and string similarities with Anchor_DNS and some similarities
to TrickBot.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=6bbe4681-573c-417b-bb91-657aef026509

https://www.cybereason.com/blog/dropping-anchor-from-a-trickbot-infection-to-the-discovery-of-the-anchor-malware

https://www.bleepingcomputer.com/news/security/trickbots-new-linux-malware-covertly-infects-windows-devices/

https://thedfirreport.com/2021/03/08/bazar-drops-the-anchor

https://attack.mitre.org/software/S0504/

https://malpedia.caad.fkie.fraunhofer.de/details/win.anchor



BlackPOS (category:
Malware)


type: POS malware, Credential stealer

(Trend Micro) In 2012, the source code of BlackPOS was leaked, enabling other
cybercriminals and attackers to enhance its code. Even though BlackPOS ver2 has
an entirely different code compared to the BlackPOS which compromised Target,
it duplicates the data exfiltration technique used by the Target BlackPOS. It
is an improved clone of the original, which is why we decided to call this
BlackPOS ver2. It is also being reported in the press that some security
vendors called this malware as “FrameworkPOS.”

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=41ad02a6-84e7-4a4a-bc6f-ac6ac0d8219b

https://blog.trendmicro.com/trendlabs-security-intelligence/new-blackpos-malware-emerges-in-the-wild-targets-retail-accounts/

https://www.welivesecurity.com/2013/12/19/target-down-biggest-data-breach-ever-leaks-40-million-credit-and-debit-cards-from-retailer-at-height-of-shopping-season/

https://blog.trendmicro.com/trendlabs-security-intelligence/home-depot-breach-linked-to-blackpos-malware/

https://labs.sentinelone.com/fin6-frameworkpos-point-of-sale-malware-analysis-internals-2/

https://www.trendmicro.de/cloud-content/us/pdfs/security-intelligence/white-papers/wp-pos-ram-scraper-malware.pdf

https://www.secureworks.com/research/point-of-sale-malware-threats

https://threatpost.com/points-of-sale-poorly-secured-facing-sophisticated-attacks/106027/

https://malpedia.caad.fkie.fraunhofer.de/details/win.blackpos

https://otx.alienvault.com/browse/pulses?q=tag:blackpos

https://otx.alienvault.com/browse/pulses?q=tag:FrameworkPOS



CmdSQL (category:
Tools)


type: Backdoor

A component of \'Metasploit\'.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=66309c30-f6e5-4803-b57b-70f8461feffd

https://usa.visa.com/dam/VCOM/global/support-legal/documents/fin6-cybercrime-group-expands-threat-To-ecommerce-merchants.pdf



Cobalt
Strike (category: Tools)


type: Backdoor, Vulnerability scanner, Keylogger, Tunneling, Loader,
Exfiltration

Cobalt Strike is a paid penetration testing product that allows an attacker to
deploy an agent named \'Beacon\' on the victim machine. Beacon includes a wealth
of functionality to the attacker, including, but not limited to command
execution, key logging, file transfer, SOCKS proxying, privilege escalation,
mimikatz, port scanning and lateral movement. Beacon is in-memory/file-less, in
that it consists of stageless or multi-stage shellcode that once loaded by
exploiting a vulnerability or executing a shellcode loader, will reflectively
load itself into the memory of a process without touching the disk. It supports
C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and
reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit
for developing shellcode loaders, called Artifact Kit. The Beacon implant has
become popular amongst targeted attackers and criminal users as it is well
written, stable, and highly customizable.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7ea8d070-cfd7-473c-a615-437fc292af55

https://www.cobaltstrike.com/

https://www.fireeye.com/blog/threat-research/2017/06/phished-at-the-request-of-counsel.html

https://blogs.jpcert.or.jp/en/2018/08/volatility-plugin-for-detecting-cobalt-strike-beacon.html

https://github.com/JPCERTCC/aa-tools/blob/master/cobaltstrikescan.py

https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html

http://blog.morphisec.com/new-global-attack-on-point-of-sale-systems

https://www.lac.co.jp/lacwatch/people/20180521_001638.html

https://www.pentestpartners.com/security-blog/cobalt-strike-walkthrough-for-red-teamers/

https://www.bleepingcomputer.com/news/security/threat-actors-use-older-cobalt-strike-versions-to-blend-in/

https://documents.trendmicro.com/assets/white_papers/wp-cashing-in-on-atm-malware.pdf

https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html

https://www.bleepingcomputer.com/news/security/alleged-source-code-of-cobalt-strike-toolkit-shared-online/

https://www.darkreading.com/threat-intelligence/how-to-identify-cobalt-strike-on-your-network/a/d-id/1339357

https://www.deepinstinct.com/2021/03/18/cobalt-strike-post-exploitation-attackers-toolkit/

https://www.darkreading.com/attacks-breaches/cobalt-strike-becomes-a-preferred-hacking-tool-by-cybercrime-apt-groups/d/d-id/1341073

http://www.intel471.com/blog/cobalt-strike-cybercriminals-trickbot-qbot-hancitor

https://blog.malwarebytes.com/researchers-corner/2021/06/cobalt-strike-a-penetration-testing-tool-popular-among-criminals/

https://www.proofpoint.com/us/blog/threat-insight/cobalt-strike-favorite-tool-apt-crimeware

https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/

https://www.intezer.com/blog/malware-analysis/cobalt-strike-detect-this-persistent-threat/

https://www.intezer.com/blog/malware-analysis/vermilionstrike-reimplementation-cobaltstrike/

https://www.recordedfuture.com/detect-cobalt-strike-inside-look/

https://elis531989.medium.com/the-squirrel-strikes-back-analysis-of-the-newly-emerged-cobalt-strike-loader-squirrelwaffle-937b73dbd9f9

https://blog.nviso.eu/2021/10/21/cobalt-strike-using-known-private-keys-to-decrypt-traffic-part-1/

https://www.cybereason.com/blog/threat-analysis-report-all-paths-lead-to-cobalt-strike-icedid-emotet-and-qbot

https://asec.ahnlab.com/en/31811/

https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2-profile/

https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encoding-decoding/

https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption/

https://securityintelligence.com/posts/analysis-rce-vulnerability-cobalt-strike/

https://cloud.google.com/blog/products/identity-security/making-cobalt-strike-harder-for-threat-actors-to-abuse

https://unit42.paloaltonetworks.com/cobalt-strike-memory-analysis/

https://securityintelligence.com/posts/defining-cobalt-strike-reflective-loader/

https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2/

https://asec.ahnlab.com/en/59110/

https://unit42.paloaltonetworks.com/attackers-exploit-public-cobalt-strike-profiles/

https://www.europol.europa.eu/media-press/newsroom/news/europol-coordinates-global-action-against-criminal-abuse-of-cobalt-strike

https://attack.mitre.org/software/S0154/

https://malpedia.caad.fkie.fraunhofer.de/details/win.cobalt_strike

https://otx.alienvault.com/browse/pulses?q=tag:Cobalt%20Strike



FlawedAmmyy (category:
Malware)


type: Backdoor, Info stealer, Credential stealer, Exfiltration

(Proofpoint) Ammyy Admin is a popular remote access tool used by businesses and
consumers to handle remote control and diagnostics on Microsoft Windows
machines. However, leaked source code for Version 3 of Ammyy Admin has emerged
as a Remote Access Trojan called FlawedAmmyy appearing in a variety of
malicious campaigns. For infected individuals, this means that attackers
potentially have complete access to their PCs, giving threat actors the ability
to access a variety of services, steal files and credentials, and much more. We
have seen FlawedAmmyy in both massive campaigns, potentially creating a large
base of compromised computers, as well as targeted campaigns that create
opportunities for actors to steal customer data, proprietary information, and
more.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=12a4f267-6f13-4033-a9c9-f797fb2ebd45

https://www.proofpoint.com/us/threat-insight/post/leaked-ammyy-admin-source-code-turned-malware

https://www.sans.org/reading-room/whitepapers/reverseengineeringmalware/unpacking-decrypting-flawedammyy-38930

https://secrary.com/ReversingMalware/AMMY_RAT_Downloader/

https://www.proofpoint.com/us/threat-insight/post/ta505-abusing-settingcontent-ms-within-pdf-files-distribute-flawedammyy-rat

https://github.com/Coldzer0/Ammyy-v3

https://attack.mitre.org/software/S0381/

https://malpedia.caad.fkie.fraunhofer.de/details/win.flawedammyy

https://otx.alienvault.com/browse/pulses?q=tag:flawedammyy



Grateful
POS (category: Malware)


type: POS malware, Info stealer

POS malware targets systems that run physical point-of-sale device and operates
by inspecting the process memory for data that matches the structure of credit
card data (Track1 and Track2 data), such as the account number, expiration
date, and other information stored on a card’s magnetic stripe. After the cards
are first scanned, the personal account number (PAN) and accompanying data sit
in the point-of-sale system’s memory unencrypted while the system determines
where to send it for authorization. Masked as the LogMein software, the
GratefulPOS malware appears to have emerged during the fall 2017 shopping
season with low detection ratio according to some of the earliest detections
displayed on VirusTotal. The first sample was upload in November 2017. Additionally,
this malware appears to be related to the \'BlackPOS\' malware, which was linked
to some of the high-profile merchant breaches in the past.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=5fd2dd27-ea9b-4c29-b6fd-b64ee1a5c0bb

https://www2.fireeye.com/rs/848-DID-242/images/rpt-fin6.pdf

https://www.vkremez.com/2017/12/lets-learn-reversing-grateful-point-of.html

https://community.rsa.com/community/products/netwitness/blog/2017/12/08/gratefulpos-credit-card-stealing-malware-just-in-time-for-the-shopping-season

https://malpedia.caad.fkie.fraunhofer.de/details/win.grateful_pos



JSPSPY (category:
Tools)


type: Backdoor

A component of \'Metasploit\'.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=dfe95176-efcf-4774-84f8-b6b236f869d8

https://usa.visa.com/dam/VCOM/global/support-legal/documents/fin6-cybercrime-group-expands-threat-To-ecommerce-merchants.pdf



Living
off the Land (category: Tools)


(Talos) Attackers\' trends tend to come and go. But one popular technique we\'re
seeing at this time is the use of living-off-the-land binaries — or \'LoLBins\'.
LoLBins are used by different actors combined with fileless malware and
legitimate cloud services to improve chances of staying undetected within an
organisation, usually during post-exploitation attack phases.
Living-off-the-land tactics mean that attackers are using pre-installed tools
to carry out their work. This makes it more difficult for defenders to detect
attacks and researchers to identify the attackers behind the campaign. In the
attacks we\'re seeing, there are binaries supplied by the victim\'s operating
system that are normally used for legitimate purposes, but in these cases, are
being abused by the attackers. (LOLBAS Project) The goal of the LOLBAS project
is to document every binary, script, and library that can be used for Living
Off The Land techniques. A LOLBin/Lib/Script must: • Be a Microsoft-signed
file, either native to the OS or downloaded from Microsoft. • Have extra
\'unexpected\' functionality. It is not interesting to document intended use
cases. o Exceptions are application whitelisting bypasses • Have functionality
that would be useful to an APT or red team Interesting functionality can
include: • Executing code o Arbitrary code execution o Pass-through execution
of other programs (unsigned) or scripts (via a LOLBin) • Compiling code • File
operations o Downloading o Upload o Copy • Persistence o Pass-through
persistence utilizing existing LOLBin o Persistence (e.g. hide data in ADS,
execute at logon) • UAC bypass • Credential theft • Dumping process memory •
Surveillance (e.g. keylogger, network trace) • Log evasion/modification • DLL
side-loading/hijacking without being relocated elsewhere in the filesystem.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d54e09cf-97b7-40a4-b30e-4c0a2bf0ea40

https://github.com/LOLBAS-Project/LOLBAS

https://lolbas-project.github.io/

https://blog.talosintelligence.com/2019/11/hunting-for-lolbins.html

https://www.microsoft.com/security/blog/2021/03/09/azure-lolbins-protecting-against-the-dual-use-of-virtual-machine-extensions/

https://www.darkreading.com/edge-articles/is-an-attacker-living-off-your-land-

https://www.cybereason.com/blog/threat-hunting-from-lolbins-to-your-crown-jewels

https://pentera.io/blog/the-lol-isnt-so-funny-when-it-bites-you-in-the-bas/

https://www.darkreading.com/vulnerabilities-threats/as-lotl-attacks-evolve-so-must-defenses

https://otx.alienvault.com/browse/pulses?q=tag:lolbin



LockerGoga (category:
Malware)


type: Ransomware, Big Game Hunting

(Fortinet) The binary for this particular variant of LockerGoga does not
utilize any type of security evasion or obfuscation. Instead, the binary only
goes as far as encoding the RSA public key that is used in its later stages for
file encryption. It’s possible to speculate that the attackers may have already
been fully aware of the target companies’ security measures, and were therefore
confident that their malware would not be intercepted even without any
obfuscation. Another interesting fact is that the malware uses open-source
Boost libraries for its filesystem, and inter-process communication and
Crypto++ (Cryptopp) for file encryption. One of the advantages of using these
libraries is easier development and implementation since developers only need
to work with wrapper functions instead of calling individual native APIs to
achieve the same goal. And since this utilizes a higher level of programming,
statically and dynamically analysing the application without source code is
more complicated than just reading a straight sequence of Windows APIs.
However, since they do not use standard libraries, they need to be manually
linked and the functions need to be physically added to the final binary, which
results a larger file size than usual.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8cdd2a40-7ddd-4caf-b7d0-94af5984a979

https://www.fortinet.com/blog/threat-research/lockergoga-ransomeware-targeting-critical-infrastructure.html

https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/what-you-need-to-know-about-the-lockergoga-ransomware

https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html

https://www.abuse.io/lockergoga.txt

https://doublepulsar.com/how-lockergoga-took-down-hydro-ransomware-used-in-targeted-attacks-aimed-at-big-business-c666551f5880

https://www.bleepingcomputer.com/news/security/new-lockergoga-ransomware-allegedly-used-in-altran-attack/

https://attack.mitre.org/software/S0372/

https://malpedia.caad.fkie.fraunhofer.de/details/win.lockergoga

https://otx.alienvault.com/browse/pulses?q=tag:LockerGoga

https://www.bleepingcomputer.com/news/security/bitdefender-releases-free-decryptor-for-lockergoga-ransomware/



Magecart (category:
Malware)


type: Info stealer

(RiskIQ) Magecart is a rapidly growing cybercrime syndicate comprised of dozens
of subgroups that specialize in cyberattacks involving digital credit card
theft by skimming online payment forms. Magecart also refers to the JavaScript
code those groups inject.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=88d973c6-16d8-4e6d-bba3-1e4c746e8651

https://www.riskiq.com/what-is-magecart/

https://malpedia.caad.fkie.fraunhofer.de/details/js.magecart

https://otx.alienvault.com/browse/pulses?q=tag:Magecart



Meterpreter (category:
Tools)


type: Loader

Meterpreter is an advanced, dynamically extensible payload that uses in-memory
DLL injection stagers and is extended over the network at runtime. It
communicates over the \'Metasploit Stager\' socket and provides a comprehensive
client-side Ruby API. It features command history, tab completion, channels,
and more. Meterpreter was originally written by skape for \'Metasploit\' 2.x,
common extensions were merged for 3.x and is currently undergoing an overhaul
for Metasploit 3.3. The server portion is implemented in plain C and is now
compiled with MSVC, making it somewhat portable. The client can be written in
any language but Metasploit has a full-featured Ruby client API.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=764acaf2-f0a0-4e7c-9933-d556cf0eb645

https://github.com/r00t-3xp10it/meterpeter

https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/

https://malpedia.caad.fkie.fraunhofer.de/details/win.meterpreter

https://malpedia.caad.fkie.fraunhofer.de/details/apk.meterpreter

https://otx.alienvault.com/browse/pulses?q=tag:Meterpreter



Mimikatz (category:
Tools)


type: Credential stealer, Keylogger

(SANS) Mimikatz provides a wealth of tools for collecting and making use of
Windows credentials on target systems, including retrieval of cleartext
passwords, Lan Manager hashes, and NTLM hashes, certificates, and Kerberos
tickets. The tools run with varying success on all versions of Windows from XP
forward, with functionality somewhat limited in Windows 8.1 and later.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8f0da519-c1bc-4add-9e04-2c429e74564f

https://github.com/gentilkiwi/mimikatz

https://www.sans.org/reading-room/whitepapers/intrusion/mimikatz-overview-defenses-detection-36780

https://www.wired.com/story/how-mimikatz-became-go-to-hacker-tool/

https://www.crowdstrike.com/blog/credential-theft-mimikatz-techniques/

https://attack.mitre.org/software/S0002/

https://malpedia.caad.fkie.fraunhofer.de/details/win.mimikatz

https://otx.alienvault.com/browse/pulses?q=tag:mimikatz



More_eggs (category:
Malware)


type: Backdoor, Downloader

More_eggs is a JavaScript backdoor used by the Cobalt group. It attempts to
connect to its C&C server and retrieve tasks to carry out, some of which
are: - d&exec = download and execute PE file - gtfo = delete files/startup
entries and terminate - more_eggs = download additional/new scripts -
more_onion = run new script and terminate current script - more_power = run
command shell commands

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a23df665-46df-4134-8375-0b05c14f617b

https://securityintelligence.com/posts/more_eggs-anyone-threat-actor-itg08-strikes-again/

https://blog.trendmicro.com/trendlabs-security-intelligence/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses/

https://reaqta.com/2018/03/spear-phishing-campaign-leveraging-msxsl/

https://www.secureworks.com/blog/cybercriminals-increasingly-trying-to-ensnare-the-big-financial-fish

https://blog.trendmicro.com/trendlabs-security-intelligence/cobalt-spam-runs-use-macros-cve-2017-8759-exploit/

https://blog.talosintelligence.com/2018/07/multiple-cobalt-personality-disorder.html

https://www.proofpoint.com/us/threat-insight/post/fake-jobs-campaigns-delivering-moreeggs-backdoor-fake-job-offers

https://asert.arbornetworks.com/double-the-infection-double-the-fun/

https://quointelligence.eu/2018/11/golden-chickens-uncovering-a-malware-as-a-service-maas-provider-and-two-new-threat-actors-using/

https://www.esentire.com/blog/hackers-spearphish-corporate-hiring-managers-with-poisoned-resumes-infecting-them-with-the-more-eggs-malware

https://www.esentire.com/blog/more-eggs-activity-persists-via-fake-job-applicant-lures

https://attack.mitre.org/software/S0284/

https://malpedia.caad.fkie.fraunhofer.de/details/js.more_eggs

https://otx.alienvault.com/browse/pulses?q=tag:More_eggs



Ryuk (category:
Malware)


type: Ransomware, Big Game Hunting

Ryuk is a ransomware which encrypts its victim\'s files and asks for a ransom
via bitcoin to release the original files. It is has been observed being used
to attack companies or professional environments. Cybersecurity experts figured
out that Ryuk and \'Hermes\' ransomware shares pieces of codes. Hermes is
commodity ransomware that has been observed for sale on dark-net forums and
used by multiple threat actors.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=7ecebee3-176f-47c2-9b9d-4d086f283711

https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/

https://www.csoonline.com/article/3541810/ryuk-ransomware-explained-a-targeted-devastatingly-effective-attack.html

https://www.cybereason.com/blog/triple-threat-emotet-deploys-trickbot-to-steal-data-spread-ryuk-ransomware

https://research.checkpoint.com/ryuk-ransomware-targeted-campaign-break/

https://www.fireeye.com/blog/threat-research/2019/01/a-nasty-trick-from-credential-theft-malware-to-business-disruption.html

https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html

https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/ryuk-ransomware-attack-rush-to-attribution-misses-the-point/

https://thedfirreport.com/2020/10/08/ryuks-return/

https://cofense.com/the-ryuk-threat-why-bazarbackdoor-matters-most/

https://www.deepinstinct.com/2020/11/24/ryuk-ransomware-the-deviance-is-in-the-variance/

https://www.cybereason.com/blog/cybereason-vs.-ryuk-ransomware

https://www.advanced-intel.com/post/crime-laundering-primer-inside-ryuk-crime-crypto-ledger-risky-asian-crypto-traders

https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-006.pdf

https://www.darkreading.com/vulnerabilities---threats/ryuks-rampage-has-lessons-for-the-enterprise/a/d-id/1340533

https://www.advanced-intel.com/post/adversary-dossier-ryuk-ransomware-anatomy-of-an-attack-in-2021

https://news.sophos.com/en-us/2021/05/06/mtr-in-real-time-pirates-pave-way-for-ryuk-ransomware/

https://securityintelligence.com/articles/ryuk-ransomware-operators-shift-tactics/

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/new-ryuk-ransomware-sample%e2%80%aftargets-webservers/

https://attack.mitre.org/software/S0446/

https://malpedia.caad.fkie.fraunhofer.de/details/win.ryuk

https://otx.alienvault.com/browse/pulses?q=tag:Ryuk

https://pan-unit42.github.io/playbook_viewer/?pb=ryuk-ransomware



SCRAPMINT (category:
Malware)


type: POS malware, Credential stealer

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a5b0bcbe-9db1-474a-ba6c-4f79a02f48f1



TerraStealer (category:
Malware)


type: Reconnaissance

According to QuoINT, TerraStealer (also known as SONE or StealerOne) is a
generic reconnaissance tool, targeting for example email clients, web browsers,
and file transfer utilities. Attributed to Golden Chickens.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=699df5d6-f8dc-43ff-8148-d652b76dfdbd

https://quointelligence.eu/2020/01/the-chicken-keeps-laying-new-eggs-uncovering-new-gc-maas-tools-used-by-top-tier-threat-actors/

https://malpedia.caad.fkie.fraunhofer.de/details/win.terra_stealer



Vawtrak (category:
Malware)


type: Banking trojan, Info stealer, Credential stealer, Botnet

(Sophos) Vawtrak is an information stealing malware family that is primarily
used to gain unauthorised access to bank accounts through online banking
websites. Machines infected by Vawtrak form part of a botnet that collectively
harvests login credentials for the online accounts to a wide variety of
financial and other industry organisations. These stolen credentials are used,
in combination with injected code and by proxying through the victim’s machine,
to initiate fraudulent transfers to bank accounts controlled by the Vawtrak
botnet administrators.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a40177a1-056d-489e-b91b-8d7fbc03e068

https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-vawtrak-international-crimeware-as-a-service-tpna.pdf

https://www.kaspersky.com/blog/neverquest-trojan-built-to-steal-from-hundreds-of-banks/3247/

https://www.blueliv.com/downloads/network-insights-into-vawtrak-v2.pdf

https://info.phishlabs.com/blog/the-unrelenting-evolution-of-vawtrak

https://threatpost.com/pos-attacks-net-crooks-20-million-stolen-bank-cards/117595/

https://www.fidelissecurity.com/threatgeek/2016/05/vawtrak-trojan-bank-it-evolving

http://thehackernews.com/2017/01/neverquest-fbi-hacker.html

https://blog.fox-it.com/2018/08/09/bokbot-the-rebirth-of-a-banker/

https://www.proofpoint.com/us/threat-insight/post/In-The-Shadows

https://www.crowdstrike.com/blog/sin-ful-spiders-wizard-spider-and-lunar-spider-sharing-the-same-web/

https://lokalhost.pl/gozi_tree.txt

https://malpedia.caad.fkie.fraunhofer.de/details/win.vawtrak

https://otx.alienvault.com/browse/pulses?q=tag:vawtrak



Windows
Credentials Editor (category: Tools)


type: Credential stealer

Windows Credentials Editor (WCE) is a security tool to list logon sessions and
add, change, list and delete associated credentials (ex.: LM/NT hashes,
plaintext passwords and Kerberos tickets).

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=80139ef6-2f4b-480e-8f45-f5cad853fa8d

https://www.ampliasecurity.com/research/windows-credentials-editor/

https://attack.mitre.org/software/S0005/



TTP













T1134

[FIN6] has used has used Metasploit’s named-pipe impersonation technique to
escalate privileges.(Citation: FireEye FIN6 Apr 2019)



T1087

T1087.002

[FIN6] has used Metasploit’s [PsExec](https://attack.mitre.org/software/S0029)
NTDSGRAB module to obtain a copy of the victim\'s Active Directory
database.(Citation: FireEye FIN6 April 2016)



T1560

Following data collection, [FIN6] has compressed log files into a ZIP archive
prior to staging and exfiltration.(Citation: FireEye FIN6 April 2016)



T1560.003

[FIN6] has encoded data gathered from the victim with a simple substitution
cipher and single-byte XOR using the 0xAA key, and Base64 with character
permutation.(Citation: FireEye FIN6 April 2016)(Citation: Trend Micro FIN6
October 2019)



T1119

[FIN6] has used a script to iterate through a list of compromised PoS systems,
copy and remove data to a log file, and to bind to events from the submit
payment button.(Citation: FireEye FIN6 April 2016)(Citation: Trend Micro FIN6
October 2019)



T1547

T1547.001

[FIN6] has used Registry Run keys to establish persistence for its downloader
tools known as HARDTACK and SHIPBREAD.(Citation: FireEye FIN6 April 2016)



T1110

T1110.002

[FIN6] has extracted password hashes from ntds.dit to crack offline.(Citation:
FireEye FIN6 April 2016)



T1059

[FIN6] has used scripting to iterate through a list of compromised PoS systems,
copy data to a log file, and remove the original data files.(Citation: FireEye
FIN6 April 2016)(Citation: FireEye FIN6 Apr 2019)



T1059.001

[FIN6] has used PowerShell to gain access to merchant\'s networks, and a
Metasploit PowerShell module to download and execute shellcode and to set up a
local listener.(Citation: FireEye FIN6 April 2016)(Citation: FireEye FIN6 Apr
2019)(Citation: Visa FIN6 Feb 2019)



T1059.003

[FIN6] has used kill.bat script to disable security tools.(Citation: FireEye
FIN6 Apr 2019)



T1059.007

[FIN6] has used malicious JavaScript to steal payment card data from e-commerce
sites.(Citation: Trend Micro FIN6 October 2019)



T1555

[FIN6] has used the Stealer One credential stealer to target e-mail and file
transfer utilities including FTP.(Citation: Visa FIN6 Feb 2019)



T1555.003

[FIN6] has used the Stealer One credential stealer to target web
browsers.(Citation: Visa FIN6 Feb 2019)



T1213

[FIN6] has collected schemas and user accounts from systems running SQL
Server.(Citation: Visa FIN6 Feb 2019)



T1005

[FIN6] has collected and exfiltrated payment card data from compromised
systems.(Citation: Trend Micro FIN6 October 2019)(Citation: RiskIQ British
Airways September 2018)(Citation: RiskIQ Newegg September 2018)



T1074

T1074.002

[FIN6] actors have compressed data from remote systems and moved it to another
staging system before exfiltration.(Citation: FireEye FIN6 April 2016)



T1573

T1573.002

[FIN6] used the Plink command-line utility to create SSH tunnels to C2
servers.(Citation: FireEye FIN6 April 2016)



T1048

T1048.003

[FIN6] has sent stolen payment card data to remote servers via HTTP
POSTs.(Citation: Trend Micro FIN6 October 2019)



T1068

[FIN6] has used tools to exploit Windows vulnerabilities in order to escalate
privileges. The tools targeted CVE-2013-3660, CVE-2011-2005, and CVE-2010-4398,
all of which could allow local users to access kernel-level
privileges.(Citation: FireEye FIN6 April 2016)



T1562

T1562.001

[FIN6] has deployed a utility script named kill.bat to disable
anti-virus.(Citation: FireEye FIN6 Apr 2019)



T1070

T1070.004

[FIN6] has removed files from victim machines.(Citation: FireEye FIN6 April
2016)



T1036

T1036.004

[FIN6] has renamed the \"psexec\" service name to \"mstdc\" to
masquerade as a legitimate Windows service.(Citation: FireEye FIN6 Apr 2019)



T1046

[FIN6] used publicly available tools (including Microsoft\'s built-in SQL
querying tool, osql.exe) to map the internal network and conduct reconnaissance
against Active Directory, Structured Query Language (SQL) servers, and
NetBIOS.(Citation: FireEye FIN6 April 2016)



T1095

[FIN6] has used Metasploit Bind and Reverse TCP stagers.(Citation: Trend Micro
FIN6 October 2019)



T1027

T1027.010

[FIN6] has used encoded PowerShell commands.(Citation: Visa FIN6 Feb 2019)



T1588

T1588.002

[FIN6] has obtained and used tools such as
[Mimikatz](https://attack.mitre.org/software/S0002), [Cobalt
Strike](https://attack.mitre.org/software/S0154), and
[AdFind](https://attack.mitre.org/software/S0552).(Citation: Security
Intelligence More Eggs Aug 2019)(Citation: FireEye FIN6 Apr 2019)



T1003

T1003.001

[FIN6] has used [Windows Credential
Editor](https://attack.mitre.org/software/S0005) for credential
dumping.(Citation: FireEye FIN6 April 2016)(Citation: FireEye FIN6 Apr 2019)



T1003.003

[FIN6] has used Metasploit’s [PsExec](https://attack.mitre.org/software/S0029)
NTDSGRAB module to obtain a copy of the victim\'s Active Directory
database.(Citation: FireEye FIN6 April 2016)(Citation: FireEye FIN6 Apr 2019)



T1566

T1566.001

[FIN6] has targeted victims with e-mails containing malicious
attachments.(Citation: Visa FIN6 Feb 2019)



T1566.003

[FIN6] has used fake job advertisements sent via LinkedIn to spearphish
targets.(Citation: Security Intelligence More Eggs Aug 2019)



T1572

[FIN6] used the Plink command-line utility to create SSH tunnels to C2
servers.(Citation: FireEye FIN6 April 2016)



T1021

T1021.001

[FIN6] used RDP to move laterally in victim networks.(Citation: FireEye FIN6
April 2016)(Citation: FireEye FIN6 Apr 2019)



T1018

[FIN6] used publicly available tools (including Microsoft\'s built-in SQL
querying tool, osql.exe) to map the internal network and conduct reconnaissance
against Active Directory, Structured Query Language (SQL) servers, and
NetBIOS.(Citation: FireEye FIN6 April 2016)



T1053

T1053.005

[FIN6] has used scheduled tasks to establish persistence for various malware it
uses, including downloaders known as HARDTACK and SHIPBREAD and
[FrameworkPOS](https://attack.mitre.org/software/S0503).(Citation: FireEye FIN6
April 2016)



T1553

T1553.002

[FIN6] has used Comodo code-signing certificates.(Citation: Security
Intelligence More Eggs Aug 2019)



T1569

T1569.002

[FIN6] has created Windows services to execute encoded PowerShell
commands.(Citation: FireEye FIN6 Apr 2019)



T1204

T1204.002

[FIN6] has used malicious documents to lure victims into allowing execution of
PowerShell scripts.(Citation: Visa FIN6 Feb 2019)



T1078

To move laterally on a victim network, [FIN6] has used credentials stolen from
various systems on which it gathered usernames and password hashes.(Citation:
FireEye FIN6 April 2016)(Citation: FireEye FIN6 Apr 2019)(Citation: Visa FIN6
Feb 2019)



T1102

[FIN6] has used Pastebin and Google Storage to host content for their
operations.(Citation: FireEye FIN6 Apr 2019)



T1047

[FIN6] has used WMI to automate the remote execution of PowerShell
scripts.(Citation: Security Intelligence More Eggs Aug 2019)


Alternate Group Names
ATK88Camouflage TempestG0037GOLD FRANKLINITG08MageCart Group 6SKELETON SPIDERWhite Giant


Comments
new comment
Nobody has commented yet. Will you be the first?
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.