logo

FIN8__2021__Bitdefender-PR-Whitepaper-FIN8-creat5619-en-EN.pdf

ID: 04eaa9aa-5b5a-49cb-8439-456729b01913

STIX ID: report--04eaa9aa-5b5a-49cb-8439-456729b01913

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2021-08-24

Last Modified Date: 2021-08-24

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Bitdefender details a forensic analysis of FIN8’s emerging ‘Sardonic’ backdoor discovered in a real-world infection: the report documents the multi-stage loader (PowerShell → WMI-persisted .NET DLL → downloader shellcode), WMI-based persistence triggers, downloader and C2 protocol behavior (custom binary protocol over port 443 with optional RC4/RSA key exchange), a fileless plugin system, observed TTPs (Impacket tools, lateral movement), IoCs (domains, IPs, hashes, filenames, WMI objects), and defensive recommendations for detection and containment.