G0037

G0037FIN6

Description

[FIN6](https://attack.mitre.org/groups/G0037) is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.(Citation: FireEye FIN6 April 2016)(Citation: FireEye FIN6 Apr 2019)

References

  1. https://attack.mitre.org/groups/G0037
  2. https://crowdstrike.lookbookhq.com/global-threat-report-2018-web/cs-2018-global-threat-report
  3. https://www2.fireeye.com/rs/848-DID-242/images/rpt-fin6.pdf
  4. https://www.fireeye.com/blog/threat-research/2019/04/pick-six-intercepting-a-fin6-intrusion.html
  5. https://securityintelligence.com/posts/itg08-aka-fin6-partners-with-trickbot-gang-uses-anchor-framework/
  6. https://securityintelligence.com/posts/more_eggs-anyone-threat-actor-itg08-strikes-again/

Software attributed to this2

TypeTargetConfidenceTier
SoftwareMore_eggss0284100%live
SoftwareFrameworkPOSs050395%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
FIN8
Group
FIN7
Group
FIN5
Software
FrameworkPOS
Group
FIN10
Group
FIN13
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.