FIN6, Skeleton Spider

Description

FIN6 is a cybercrime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.

(FireEye) FIN6 is a cybercriminal group intent on stealing payment card data for monetization. In 2015, FireEye Threat Intelligence supported several Mandiant Consulting investigations in the hospitality and retail sectors where FIN6 actors had aggressively targeted and compromised point-of-sale (POS) systems, making off with millions of payment card numbers. Through iSIGHT, we learned that the payment card numbers stolen by FIN6 were sold on a “card shop” — an underground criminal marketplace used to sell or exchange payment card data.

Names

NameName-Giver
FIN6FireEye
Skeleton SpiderCrowdStrike
Gold FranklinSecureworks
White GiantPWC
ITG08IBM
ATK 88Thales
TAG-CR2Recorded Future
TAALMicrosoft
Storm-0538Microsoft
Camouflage TempestMicrosoft

Country

Motivation

  • Financial crime
  • Financial gain

First Seen

2015

Observed Sectors

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

61c8ecd4-e4e1-4f36-b209-ca55106ec22f

Last Card Change

2025-06-28