Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0037
MITRE ATT&CK Group

FIN6 (G0037)

Magecart Group 6ITG08Skeleton SpiderTAALCamouflage Tempest
ShareXLinkedInRedditHN

[FIN6](https://attack.mitre.org/groups/G0037) is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in the hospitality and retail sectors.(Citation: FireEye FIN6 April 2016)(Citation: FireEye FIN6 Apr 2019)

▪Techniques used (40)

T1560.003Archive via Custom MethodT1566.001Spearphishing AttachmentT1685Disable or Modify ToolsT1087.002Domain AccountT1059Command and Scripting InterpreterT1572Protocol TunnelingT1213.006DatabasesT1027.010Command ObfuscationT1059.007JavaScriptT1102Web ServiceT1005Data from Local SystemT1547.001Registry Run Keys / Startup FolderT1059.003Windows Command ShellT1588.002ToolT1070.004File DeletionT1003.003NTDST1134Access Token ManipulationT1068Exploitation for Privilege EscalationT1204.002Malicious FileT1036.004Masquerade Task or ServiceT1566.003Spearphishing via ServiceT1059.001PowerShellT1560Archive Collected DataT1553.002Code SigningT1021.001Remote Desktop ProtocolT1119Automated CollectionT1018Remote System DiscoveryT1053.005Scheduled TaskT1569.002Service ExecutionT1046Network Service DiscoveryT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1047Windows Management InstrumentationT1110.002Password CrackingT1555Credentials from Password StoresT1095Non-Application Layer ProtocolT1078Valid AccountsT1573.002Asymmetric CryptographyT1003.001LSASS MemoryT1555.003Credentials from Web BrowsersT1074.002Remote Data Staging

▪Software used (12)

S0381FlawedAmmyymalwareS0632GrimAgentmalwareS0503FrameworkPOSmalwareS0284More_eggsmalwareS0154Cobalt StrikemalwareS0005Windows Credential EditortoolS0552AdFindtoolS0029PsExectoolS0449MazemalwareS0372LockerGogamalwareS0446RyukmalwareS0002Mimikatztool
G0037on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.