FIN6__2016__Fireeye_rpt-fin6_04-20-2018.pdf
ID: 21ffe2a6-e416-488a-9bfd-ab18d88f2659
STIX ID: report--21ffe2a6-e416-488a-9bfd-ab18d88f2659
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2016-04-15
Last Modified Date: 2016-04-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This FireEye report analyzes FIN6, a financially motivated cyber crime group that conducted large-scale point-of-sale compromises using credential-stealing malware (GRABNEW) and POS memory-scraping malware (TRINITY). The report covers FIN6's attack lifecycle — initial access, lateral movement, privilege escalation, persistence, data collection and exfiltration — and links stolen payment card data to underground "card shop" marketplaces where millions of cards were sold and monetized, resulting in significant fraud losses.
