FIN8 harvests credentials using Invoke-Mimikatz or Windows Credentials Editor (WCE).5
group
FIN8 G0061
- Created
- 18 April 2018
- Last modified
- 31 July 2026
- Aliases
- FIN8 · Syssphinx
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.[1][2][3][4]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0061
FIN8 has used the Ping command to check connectivity to actor-controlled C2 servers.6
FIN8 has used dsquery and other Active Directory utilities to enumerate hosts; they have also used nltest.exe /dclist to retrieve a list of domain controllers.78
FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement.1011
FIN8 has used environment variables and standard input (stdin) to obfuscate command-line arguments. FIN8 also obfuscates malicious macros delivered as payloads.121314
Standing G0061
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
73rd percentile · 73% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
94th percentile · 94% of 176 ATT&CK groups have this many tactics spanned or fewer.
84th percentile · 84% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
80th percentile · 80% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0061
1600 distinct rules cover the 36 techniques recorded for this group. The 1759 technique-to-rule mappings resolve to 1600 distinct rules, because one rule can cover several techniques. 1047 Sigma · 553 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org