HARDTACK is a downloader associated with the financially motivated threat group FIN6. It has been used in intrusions targeting hospitality and retail organizations, particularly during point-of-sale compromise operations aimed at stealing payment card data. In FIN6 tradecraft, HARDTACK was deployed after initial compromise to reinforce attacker access and provide backdoor connectivity within victim environments, supporting follow-on deployment of additional malware used in payment-card theft operations.
Observed behavior shows HARDTACK being used on Windows systems and maintained through common persistence mechanisms including scheduled tasks and Registry Run keys. Its role in FIN6 operations was to connect to remote command-and-control infrastructure and facilitate continued access to compromised hosts, making it part of the intrusion-enablement layer rather than the final payment-card theft payload itself. HARDTACK has been documented alongside SHIPBREAD and in operations that also involved FrameworkPOS/Trinity, with FIN6 using these tools to expand and sustain access inside compromised enterprise networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader tool used by FIN6 that persists via Registry Run keys.
Downloader used by FIN6 and persisted via scheduled tasks.
Downloader tool used by FIN6 that persists via Registry Run keys.
Downloader used by FIN6 after initial access to establish backdoor connectivity to remote command-and-control servers and maintain remote control of compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.