FIN8
1 incidentes
1 paises
1 sectores
apt RU Ultimo: 2026-05-25
Aliases: ATK113, G0061, Powersniff, PUNCHBUGGY, ShellTea, lo que refleja su enfoque en ataques basados en macros
FIN8 is a financially motivated cybercrime group that began operating in January 2016, specializing in Point-of-Sale attacks and evolving into ransomware operations for increased profit. The group is distinguished by its practice of taking extended breaks between campaigns to refine its tactics, techniques, and procedures, ensuring a higher success rate upon re-emergence. Early operations focused on retail, hospitality, and financial sectors, with unique use of custom POS malware. More recently, FIN8 shifted towards distributing various ransomware variants. While its precise origin is not publicly confirmed, assessments indicate a likely operational base within the Commonwealth of Independent States region. FIN8 is also identified by aliases such as ATK113, Syssphinx, Storm-0288, and MITRE’s G0061.