FIN4 is a financially motivated cyber intrusion group known for targeting individuals and organizations to obtain nonpublic market-moving information that could be used for securities trading advantage. The group has been associated with credential theft operations focused on harvesting access to email accounts and related communications rather than disruptive or destructive activity. FIN4 commonly uses spearphishing emails with malicious attachments, often leveraging compromised accounts and stolen legitimate documents to increase credibility. The group has used embedded malicious macros, including VBA-based lures that prompt victims and collect credentials, as well as fake Outlook Web App login pages for credential harvesting. FIN4 has also deployed a .NET-based keylogger to capture victim input and credentials. Operationally, FIN4 has used HTTP POST for data transmission and has used Tor to access victim email accounts, indicating efforts to conceal operator activity and abuse compromised credentials for follow-on collection. The group’s tradecraft is consistent with targeted phishing, user execution, credential capture, and collection of sensitive business information in support of profit-driven trading activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for a Linux usermod root UID set analytic; no specific campaign or activity is described in this reference.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Referenced as a threat actor associated with the MITRE ATT&CK technique T1090.003 (Multi-hop Proxy) in the detection annotation for access to anonymizer services.
Listed as a threat actor associated with Azure Active Directory account takeover, persistence, privilege escalation, and related cloud-focused post-compromise activity detected via PowerShell module installation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.