FIN4 is a financially motivated intrusion set known for targeting individuals likely to possess confidential, market-moving information, particularly senior executives, legal counsel, and personnel involved in regulatory, risk, and compliance matters. The group has been associated with efforts to steal insider information that could provide an advantage in securities trading. FIN4 is known for spearphishing-led operations that rely heavily on social engineering and user execution. The actor has sent targeted emails with malicious attachments, including documents containing embedded VBA macros, and has used stolen legitimate documents delivered from compromised accounts to increase credibility. FIN4 has also used fake Outlook Web App login pages and macro-driven credential prompts to harvest victim credentials. Observed tradecraft includes credential theft, keylogging, and use of web protocols for data transmission. FIN4 has employed a .NET-based keylogger, used HTTP POST for data transfer, and leveraged Tor to access victim email accounts in order to obscure operator activity. The group is best characterized as a cybercrime actor focused on obtaining sensitive nonpublic information rather than deploying ransomware or destructive malware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for a Linux usermod root UID set analytic; no specific campaign or activity is described in this reference.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Referenced as a threat actor associated with the MITRE ATT&CK technique T1090.003 (Multi-hop Proxy) in the detection annotation for access to anonymizer services.
Listed as a threat actor associated with Azure Active Directory account takeover, persistence, privilege escalation, and related cloud-focused post-compromise activity detected via PowerShell module installation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.