FIN8 is a financially motivated cybercrime threat actor known for intrusions against organizations in sectors such as retail, hospitality, and payments, with activity centered on theft and monetization of payment-card data and other financially valuable information. The group is also tracked under aliases including Syssphinx and STORM-0288. FIN8 has historically combined targeted phishing and post-compromise intrusion tradecraft with custom malware and hands-on-keyboard operations to obtain initial access, expand footholds, and support follow-on fraud or data theft objectives. The actor is notable for aggressive phishing campaigns using malicious email attachments to induce user execution. After compromise, FIN8 has demonstrated broad use of native Windows tooling and scripting, including PowerShell, to profile victim systems and tailor payload deployment, such as checking host architecture before selecting an appropriate malicious .NET loader. The group has also used WMI, WMIC, and Impacket to launch malware, move laterally, and conduct cleanup. Observed reconnaissance includes user and session discovery through commands such as quser, as well as environmental checks intended to identify analysis or sandbox conditions. FIN8 employs defense-evasion and anti-analysis measures, including use of Windows Registry artifacts both to detect likely sandbox environments and to remove traces during post-compromise cleanup by deleting registry data. The group has also used HTTPS for command-and-control communications, helping blend malicious traffic with normal encrypted web activity. Reported ATT&CK-aligned behaviors associated with FIN8 include PowerShell execution, exploitation for privilege escalation, Windows service-based persistence or installation, setuid or setgid abuse in Linux-focused detections, user execution via phishing attachments, system and user discovery, registry modification, and security software discovery. FIN8 is widely regarded as an eCrime actor rather than a nation-state operator. Its operations reflect a mature intrusion capability focused on financially driven outcomes, with tradecraft spanning initial access, reconnaissance, privilege escalation, lateral movement, persistence, command and control, and cleanup.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
FIN8 has exploited the CVE-2016-0167 local vulnerability.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Referenced in the detection annotations as a threat actor associated with exploitation for privilege escalation activity.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed in the analytic annotations as a threat actor associated with exploitation for privilege escalation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.