FIN8
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
FIN8 is a financially motivated threat actor that has been publicly linked to the United States of America in open‑source reporting. The group is known by the alias FIN8 and has been observed targeting the hospitality sector, particularly point‑of‑sale environments, with the apparent goal of stealing payment card data for monetary gain. Public reporting notes that the actor’s tactics overlap with those historically associated with the FIN7 group, although no formal affiliation or state sponsorship has been asserted in the available sources. The actor’s activity has been described as financially driven, with a focus on infiltrating networks that process card‑present transactions.
Initial access for FIN8 operations has been observed through phishing campaigns that deliver a fileless variant of the ShellTea backdoor, also referred to as PunchBuggy in earlier reporting. Once executed, the malware establishes persistence by creating a registry run key under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and then launches PowerShell code stored under a randomly named subkey. The shellcode is injected into the explorer.exe process using low‑level API calls such as RtlCreateUserThread after locating the explorer process via the desktop window handle. To avoid detection, the malware employs a range of anti‑analysis techniques, including querying firmware strings via NtQuerySystemInformation to detect virtual environments, scanning running processes and comparing CRC32 hashes of process names against a blacklist that includes debuggers and monitoring tools, and validating the system’s hard‑disk volume by comparing a SHA1 hash of the volume name against a hard‑coded value. After bypassing these checks, the payload writes the persistence commands back into the registry using different XOR keys for each string to thwart simple static analysis.
Command‑and‑control communication occurs over HTTPS with proxy‑aware fallback mechanisms, leveraging Windows Internet API functions. The backdoor supports a versatile command set that includes writing received data or shellcode into the registry, reflectively loading and executing a delivered PE file, creating and executing a temporary file that is marked for deletion after a reboot, executing the existing shellcode in a new thread, and running arbitrary PowerShell commands via a downloaded Empire ReflectivePicker component. Reconnaissance is performed by a PowerShell script that gathers system and user information, network configuration, running tasks, registry‑stored email addresses, installed antivirus products, privileges, and domain or workgroup details, compresses the output with gzip, transmits it to the C2 server, and then deletes the temporary file. The ReflectivePicker leverages the Empire project’s reflective loader to invoke CorBindToRuntime and load the CLR directly from memory, while the malware also uses ole32 stream functions to manipulate downloaded data in‑memory. Infrastructure observed in reporting includes domains that mimic legitimate content‑delivery networks—such as telemerty‑cdn‑cloud[.]host, reservecdn[.]pro, wsuswin10[.]us, telemetry[.]host, and cdn‑amaznet[.]club—along with associated IP addresses like 104.193.252.162:443 and 37.1.204.87:443, noting overlap with infrastructure previously tied to FIN7 activity.
A representative campaign attributed to FIN8 occurred in March 2019, when the group targeted a hotel‑entertainment organization using a phishing‑delivered ShellTea variant. The fileless malware attempted to establish persistence, conduct reconnaissance, and deploy a point‑of‑sale payload, but the latter stage was blocked by endpoint security controls before reaching the POS terminals. The attack highlighted the actor’s use of overlapping infrastructure with FIN7 and the employment of advanced evasion techniques were noted as indicative of an evolving threat posture. This incident is frequently cited as the first high‑confidence FIN8 operation observed in 2019, illustrating the group’s continued focus on financially motivated intrusion attempts against the hospitality and retail sectors.
Incidents
Attributed incidents are available to members.
1 incident