logo

FIN6__2016__Fireeye_rpt-fin6_04-20-2018.pdf

ID: 21ffe2a6-e416-488a-9bfd-ab18d88f2659

STIX ID: report--21ffe2a6-e416-488a-9bfd-ab18d88f2659

Threat Score

80/100

Uploaded: 2026-08-14

Published Date: 2016-04-15

Last Modified Date: 2016-04-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This FireEye report analyzes FIN6, a financially motivated cyber crime group that conducted large-scale point-of-sale compromises using credential-stealing malware (GRABNEW) and POS memory-scraping malware (TRINITY). The report covers FIN6's attack lifecycle — initial access, lateral movement, privilege escalation, persistence, data collection and exfiltration — and links stolen payment card data to underground "card shop" marketplaces where millions of cards were sold and monetized, resulting in significant fraud losses.