Advisor

FIN18

1 min read
Jump to:

Summary

FIN18 is a financially motivated cyber threat group known for targeting organizations primarily in the financial sector through sophisticated application-layer attacks. The group employs advanced techniques such as web application exploitation, credential theft, and malware deployment to gain unauthorized access and exfiltrate sensitive financial data.

Key Characteristics

  • Focuses on financial institutions and related industries.
  • Utilizes web application attacks including SQL injection and cross-site scripting (XSS).
  • Deploys custom malware and remote access tools to maintain persistence.
  • Employs social engineering tactics to harvest credentials and facilitate initial access.
  • Exfiltrates sensitive financial and personal data for monetary gain.
  • Operates with a high level of operational security to evade detection.

Defensive Controls

Related Security Solutions

Security solutions relevant to defending against FIN18 attacks include web application firewalls (WAF), endpoint detection and response (EDR) platforms, intrusion detection and prevention systems (IDPS), multi-factor authentication (MFA) tools, and security information and event management (SIEM) systems for monitoring and correlating suspicious activities.

Tags: Application Attacks credential theft endpoint detection and response FIN18 financial cybercrime malware multi-factor authentication Threats & Attacks web application firewall