Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
FIN4
ID: 77f2ab704898b5917645c9de9e3b8b7b62446
Cybercrime
Cybercriminal
Threat types: Intrusion, Phishing, Data Theft
Progress: 35%
Completeness: 28%
Freshness: 50%
Operation zone: UNKNOWN
Aliases
Limited alias preview
No aliases registered.
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at least 2013. FIN4 is unique in that they do not infect victims with typical persistent malware, but rather they focus on capturing credentials authorized to access email and other non-public correspondence. Ref: https://attack.mitre.org/groups/G0085/
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1056.001 | Keylogging | TA0006 TA0009 |
|
| T1056.002 | GUI Input Capture | TA0006 TA0009 |
|
| T1059.005 | Visual Basic | TA0002 |
|
| T1071.001 | Web Protocols | TA0011 |
|
| T1090.003 | Multi-hop Proxy | TA0011 |
|
| T1114.002 | Remote Email Collection | TA0009 |
|
| T1204.001 | Malicious Link | TA0002 |
|
| T1204.002 | Malicious File | TA0002 |
|
| T1564.008 | Email Hiding Rules | TA0005 |
|
| T1566.001 | Spearphishing Attachment | TA0001 |
|
| T1566.002 | Spearphishing Link | TA0001 |
|
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.