FIN8

APT / EstatalG0061 ↗
Técnicas (MITRE ATT&CK)36
FuenteMITRE ATT&CK
0
También conocido como:ATK113G0061PUNCH COMETSyssphinx

Sobre el grupo

FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.

Cadena de ataque

Escenario plausible montado a partir de las técnicas reales del grupo, ordenadas por las fases de un ataque. Cada etapa muestra cómo suele actuar el grupo.

Severidad del arsenal55
Impacto: Alto
T1566.001T1047T1068T1003.001T1074.002T1048.003ENTRYAcceso inicialSpearphishingAttachmentEXECEjecuciónWindows ManagementInstrumentationPRIVEscalada de privilegiosExploitation forPrivilege Escalat…CREDAcceso a credencialesLSASS MemoryCOLLRecolecciónRemote DataStagingEXFILExfiltraciónExfiltration OverUnencrypted Non-C…IMPACTImpactoData Encrypted forImpact

Cadena ilustrativa derivada de las técnicas documentadas en MITRE ATT&CK — no representa un ataque específico ya ocurrido. La severidad resume el arsenal conocido (cobertura de la cadena, CVEs en explotación activa, técnicas).

Vulnerabilidades explotadas 1

CVEs que este grupo es conocido por explotar, según MITRE ATT&CK. Ordenadas por gravedad real.

El grupo FIN8 usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →