Vexday analysis
FIN6 (também referenciado como Magecart Group 6, ITG08, Skeleton Spider, TAAL e Camouflage Tempest) é um grupo cibercriminoso especializado no roubo de dados de cartões de pagamento para revenda em mercados clandestinos. O grupo tem como alvos prioritários sistemas de ponto de venda (PoS) nos setores de hospitalidade e varejo, conduzindo comprometimentos de forma agressiva e sistemática. Ao grupo são atribuídas 40 técnicas documentadas no MITRE ATT&CK (identificador G0037) e a exploração de 3 CVEs conhecidas.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 40
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities 3
CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.
Known infrastructure 1376
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
178.16.52.177:443Cobalt Strikethreatfox110.42.255.63:80Cobalt Strikethreatfox117.72.159.96:8082Cobalt Strikethreatfox117.72.159.96:8088Cobalt Strikethreatfox117.72.159.96:5003Cobalt Strikethreatfox110.42.255.63:9000Cobalt Strikethreatfox110.42.255.63:3000Cobalt Strikethreatfox172.93.221.193:22Cobalt Strikethreatfox9717F005C5FB98E08D2AD983D88F94EECobalt Strikethreatfox9460E150E1981D5C165043520C5C12FECobalt Strikethreatfox2d7c8780e97409770a9d4f31c66c9d63Cobalt Strikethreatfox172.93.221.193:8080Cobalt Strikethreatfox172.93.221.193:443Cobalt Strikethreatfox52.141.2.68:8080Cobalt Strikethreatfox52.141.2.68:50000Cobalt Strikethreatfox172.93.221.193:80Cobalt Strikethreatfox52.141.2.68:443Cobalt Strikethreatfox52.141.2.68:80Cobalt Strikethreatfox149.88.66.234:888Cobalt Strikethreatfox149.88.66.234:3306Cobalt Strikethreatfox149.88.66.234:9999Cobalt Strikethreatfox149.88.66.234:8088Cobalt Strikethreatfox149.88.66.234:22Cobalt Strikethreatfox149.88.66.234:9200Cobalt Strikethreatfox119.29.122.42:53Cobalt Strikethreatfoxc2.apamm.kdns.frCobalt Strikethreatfox38.190.196.19:22Cobalt Strikethreatfox8.163.59.20:8082Cobalt Strikethreatfox43.225.157.17:1080Cobalt Strikethreatfox47.93.42.22:22Cobalt Strikethreatfox+1376 indicators in total. See them all on the IOCs page.
References
FIN6 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →