FIN8 Enhances Its Campaigns for Advanced Privilege Escalation
ID: 535623d1-6afa-5218-9967-a7c72de49f6d
STIX ID: report--535623d1-6afa-5218-9967-a7c72de49f6d
Feed Name: Resources-2
FIN8 is a financially motivated APT active since 2016 that has shifted from POS-targeting to sophisticated, modular in-memory toolsets and double-extortion ransomware operations; the report maps FIN8’s TTPs (PowerShell fileless execution, WMI event-driven persistence, various process injection techniques including Exocet and APC/Thread hijacking, obfuscated credential theft, and token manipulation) to MITRE ATT&CK and shows how Picus Security simulates these behaviors to test and validate defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
