THREAT_ACTOR · G0061
FIN8
Also known as: FIN8, Syssphinx
Profile
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected FIN8 switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.
MITRE ATT&CK ↗Techniques
36 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1016.001 Internet Connection DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1021.002 SMB/Windows Admin SharesT1027.010 Command ObfuscationT1033 System Owner/User DiscoveryT1047 Windows Management InstrumentationT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1053.005 Scheduled TaskT1055.004 Asynchronous Procedure CallT1059.001 PowerShellT1059.003 Windows Command ShellT1068 Exploitation for Privilege EscalationT1070.004 File DeletionT1071.001 Web ProtocolsT1074.002 Remote Data StagingT1078 Valid AccountsT1082 System Information DiscoveryT1102 Web ServiceT1105 Ingress Tool TransferT1112 Modify RegistryT1134.001 Token Impersonation/TheftT1204.001 Malicious LinkT1204.002 Malicious FileT1482 Domain Trust DiscoveryT1486 Data Encrypted for ImpactT1518.001 Security Software DiscoveryT1546.003 Windows Management Instrumentation Event SubscriptionT1560.001 Archive via UtilityT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1573.002 Asymmetric CryptographyT1588.002 ToolT1588.003 Code Signing CertificatesT1685.005 Clear Windows Event Logs
Software
11 malware/tools attributed to this actor.
PsExecNetPingdsqueryPUNCHBUGGYPUNCHTRACKImpacketNltestRagnar LockerBADHATCHSardonic
Related corpus activity
10,422 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to FIN8.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,422.