FIN8
Medium ConfidenceMedium ThreatSyssphinx
FIN8 is a financially motivated threat actor that has been active since at least 2016, targeting retail, hospitality, and entertainment organizations primarily in North America. The group specializes in deploying point-of-sale malware to steal payment card data. FIN8 is known for their use of the BADHATCH and SARDONIC backdoors, as well as their careful operational security and ability to maintain long-term access to victim networks. They periodically resurface with updated tools after periods of apparent inactivity.
FIN8 is a financially motivated threat actor that has been active since at least 2016, targeting retail, hospitality, and entertainment organizations primarily in North America. The group specializes in deploying point-of-sale malware to steal payment card data. FIN8 is known for their use of the BADHATCH and SARDONIC backdoors, as well as their careful operational security and ability to maintain long-term access to victim networks. They periodically resurface with updated tools after periods of apparent inactivity.
Target Sectors
Target Regions
Attributed to Cybercriminal (No State Sponsor) (Unknown). Attribution confidence: Medium.
Future Outlook
FIN8 is expected to continue operations targeting Retail sectors.
First observed activity of FIN8
Continued active operations