THREAT_ACTOR · G0037
FIN6
Also known as: FIN6, Magecart Group 6, ITG08, Skeleton Spider, TAAL, Camouflage Tempest
Profile
FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.
MITRE ATT&CK ↗Techniques
40 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1003.003 NTDST1005 Data from Local SystemT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1027.010 Command ObfuscationT1036.004 Masquerade Task or ServiceT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1053.005 Scheduled TaskT1059 Command and Scripting InterpreterT1059.001 PowerShellT1059.003 Windows Command ShellT1059.007 JavaScriptT1068 Exploitation for Privilege EscalationT1070.004 File DeletionT1074.002 Remote Data StagingT1078 Valid AccountsT1087.002 Domain AccountT1095 Non-Application Layer ProtocolT1102 Web ServiceT1110.002 Password CrackingT1119 Automated CollectionT1134 Access Token ManipulationT1204.002 Malicious FileT1213.006 DatabasesT1547.001 Registry Run Keys / Startup FolderT1553.002 Code SigningT1555 Credentials from Password StoresT1555.003 Credentials from Web BrowsersT1560 Archive Collected DataT1560.003 Archive via Custom MethodT1566.001 Spearphishing AttachmentT1566.003 Spearphishing via ServiceT1569.002 Service ExecutionT1572 Protocol TunnelingT1573.002 Asymmetric CryptographyT1588.002 ToolT1685 Disable or Modify Tools
Software
12 malware/tools attributed to this actor.
MimikatzWindows Credential EditorPsExecCobalt StrikeMore_eggsLockerGogaFlawedAmmyyRyukMazeFrameworkPOSAdFindGrimAgent
Related corpus activity
10,059 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to FIN6.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,059.