FIN5 is a financially motivated cybercrime threat actor associated with intrusions into enterprise environments, particularly retail and payment-card ecosystems. The group has been linked to post-compromise operations involving broad internal reconnaissance, automated collection, credential access tooling, remote administration abuse, and anti-forensic cleanup. Reported tradecraft includes scanning processes across victim systems and using automated scripts to aggregate results, using command and scripting interpreters for execution, and leveraging network-mapping utilities to identify internal targets. FIN5 has also used dual-use administrative and offensive tools including customized PsExec, pwdump, Windows Credential Editor, and SDelete. To maintain access, the group has used FLIPSIDE to establish a proxy-backed backup RDP tunnel. Observed behavior indicates emphasis on persistence, reconnaissance, credential theft, lateral movement support, automated collection, and defense evasion through artifact deletion and environment cleanup. FIN5 is commonly tracked under the FIN naming convention and is distinct from other financially motivated FIN clusters such as FIN6 and FIN7.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
3 more CVEs tied to this actor tracked in Mallory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of many threat actors associated with the ATT&CK technique/detection annotation for automated collection using Windows dir piped to findstr.
Listed as a threat actor associated with the generic installation exploitation analytic, but no campaign-specific activity is described in this reference.
Mentioned only as an annotated threat actor associated with this generic Linux shared-memory execution detection.
Listed as an example threat actor associated with the detection's ATT&CK annotations; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.