SHIPBREAD is a downloader associated with the financially motivated threat group FIN6. It has been used in intrusions targeting hospitality and retail organizations, particularly during payment-card theft operations against point-of-sale environments. In FIN6 tradecraft, SHIPBREAD was deployed after initial compromise to reinforce attacker footholds and provide backdoor access within victim networks, supporting broader post-compromise activity that led to the deployment of payment-card malware such as FrameworkPOS.
Observed behavior indicates that SHIPBREAD communicates with remote command-and-control infrastructure to retrieve or execute follow-on payloads. FIN6 has used SHIPBREAD alongside another downloader, HARDTACK, as part of intrusion chains that included credential theft during initial access, subsequent expansion of access inside the environment, and persistence on compromised Windows systems. SHIPBREAD has been associated with persistence through Windows Scheduled Tasks and Registry Run keys, indicating an emphasis on surviving reboots and maintaining long-term access.
The malware is best characterized as a Windows downloader used in criminal intrusion operations focused on monetization through payment-card theft. High-confidence reporting ties it to FIN6 activity rather than to broad commodity distribution, and the available facts support its role as an access-enabling component rather than the primary card-stealing payload itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FIN6 has used scheduled tasks to establish persistence for various malware it uses, including downloaders known as HARDTACK and SHIPBREAD and FrameworkPOS.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader tool used by FIN6 that persists via Registry Run keys.
Downloader used by FIN6 and persisted via scheduled tasks.
Downloader tool used by FIN6 that persists via Registry Run keys.
Downloader used by FIN6 to establish backdoor access and connect compromised hosts to command-and-control infrastructure for remote control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.