Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Syssphinx
36
techniques
11
software
11,748
corpus matches
profile
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.
techniques
36 attributed · most-instrumented first
software
11 malware & tools attributed
PsExec
S0029
Net
S0039
Ping
S0097
dsquery
S0105
PUNCHBUGGY
S0196
PUNCHTRACK
S0197
Impacket
S0357
Nltest
S0359
Ragnar Locker
S0481
BADHATCH
S1081
read this carefully
11,748 corpus matches is not attribution
That count is indicators which exhibit techniques FIN8 is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+24 more techniques
Sardonic
S1085
showing 30 of 11,748
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.