Threat actor · all actors
FIN8G0061 unknown
aka FIN8, Syssphinx, ATK113, G0061, PUNCH COMET
Last updated: 2026-08-20
About this actor
[FIN8](https://attack.mitre.org/groups/G0061) is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, chemical, and financial sectors. In June 2021, security researchers detected [FIN8](https://attack.mitre.org/groups/G0061) switching from targeting point-of-sale (POS) devices to distributing a number of ransomware variants.(Citation: FireEye Obfuscation June 2017)(Citation: FireEye Fin8 May 2016)(Citation: Bitdefender Sardonic Aug 2021)(Citation: Symantec FIN8 Jul 2023)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
MandiantFIN financially-motivated
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 56 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1016System Network Configuration Discovery ↗T1016.001Internet Connection Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.002SMB/Windows Admin Shares ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1033System Owner/User Discovery ↗T1047Windows Management Instrumentation ↗T1048Exfiltration Over Alternative Protocol ↗T1048.003Exfiltration Over Unencrypted Non-C2 Protocol ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1055Process Injection ↗T1055.004Asynchronous Procedure Call ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1068Exploitation for Privilege Escalation ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.002Remote Data Staging ↗T1078Valid Accounts ↗T1082System Information Discovery ↗T1102Web Service ↗T1105Ingress Tool Transfer ↗T1112Modify Registry ↗T1134Access Token Manipulation ↗T1134.001Token Impersonation/Theft ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1482Domain Trust Discovery ↗T1486Data Encrypted for Impact ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1546Event Triggered Execution ↗T1546.003Windows Management Instrumentation Event Subscription ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1573Encrypted Channel ↗T1573.002Asymmetric Cryptography ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.003Code Signing Certificates ↗T1685Disable or Modify Tools ↗T1685.005Clear Windows Event Logs ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 38 / 56 | 68% |
SI-4 | 38 / 56 | 68% |
CM-2 | 36 / 56 | 64% |
SI-3 | 32 / 56 | 57% |
AC-6 | 26 / 56 | 46% |
CM-7 | 26 / 56 | 46% |
AC-3 | 24 / 56 | 43% |
CA-7 | 24 / 56 | 43% |
AC-2 | 23 / 56 | 41% |
SC-7 | 23 / 56 | 41% |
AC-4 | 20 / 56 | 36% |
AC-5 | 18 / 56 | 32% |
CM-5 | 16 / 56 | 29% |
IA-2 | 16 / 56 | 29% |
SI-7 | 15 / 56 | 27% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- FIN6 0.41
- Wizard Spider 0.40
- Play 0.38
- APT33 0.36
- Cobalt Group 0.35