FIN8
Also reported as Syssphinx, Storm-0288, ATK113, PUNCH COMET and ATK 113.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
Show all 36 techniques Show fewer
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-3333 KEV
- CVE-2010-4398 KEV
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
Show all 116 CVEs Show fewer
- CVE-2011-4369
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2013-0422 KEV ransomware
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-7331 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-4076
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8439 KEV
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0167 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-7269 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2019-7609 KEV
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-17144 KEV
- CVE-2020-4006 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2021-20016 KEV ransomware
- CVE-2021-21972 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2023-34362 KEV ransomware
- CVE-2025-55182 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackCat (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques « Threat Research Blog
Show all 30 reports Show fewer
-
APT techniques- Access Token manipulation. Token theft. Simple Cplusplus example.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT techniques- Access Token manipulation. Token theft. Simple Cplusplus example.
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
White Rabbit Continued- Sardonic and F5
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor White Rabbit Continued- Sardonic and F5
-
New Ransomware Spotted- White Rabbit and Its Evasion Tactics
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Ransomware Spotted- White Rabbit and Its Evasion Tactics
-
White Rabbit Ransomware and the F5 Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor White Rabbit Ransomware and the F5 Backdoor
-
Bitdefender-PR-Whitepaper-FIN8-creat5619-en-EN
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Bitdefender-PR-Whitepaper-FIN8-creat5619-en-EN
-
Deep dive into a FIN8 attack – A forensic investigation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep dive into a FIN8 attack – A forensic investigation
-
FIN8- BADHATCH Threat Indicator Enrichmen
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor FIN8- BADHATCH Threat Indicator Enrichmen
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN.indd
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fuel Pumps II – PoSlurp.B
-
Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Drilling Deep: A Look at Cyberattacks on the Oil and Gas Industry
-
The original link failed its last check. Original publisher Detailsfor Revoke Obfuscation Report
Newest first. Details opens the report in Explore.