logo

FIN8 Enhances Its Campaigns for Advanced Privilege Escalation

ID: 535623d1-6afa-5218-9967-a7c72de49f6d

STIX ID: report--535623d1-6afa-5218-9967-a7c72de49f6d

Feed Name: Resources-2

Threat Score
78/100

Date Published: 2025-07-02

Date Updated: 2026-07-22

Author: [email protected] (Sıla Özeren)

...
...

FIN8 is a financially motivated APT active since 2016 that has shifted from POS-targeting to sophisticated, modular in-memory toolsets and double-extortion ransomware operations; the report maps FIN8’s TTPs (PowerShell fileless execution, WMI event-driven persistence, various process injection techniques including Exocet and APC/Thread hijacking, obfuscated credential theft, and token manipulation) to MITRE ATT&CK and shows how Picus Security simulates these behaviors to test and validate defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.