Skip to main content

Boteraser | Website and Server Security Solutions

Unidentified 103 (FIN8)

Malware
╔

⚠️ Overview

Unidentified 103 (FIN8) is a backdoor malware family attributed to the financially motivated threat group FIN8 (also tracked as Sphinx or FIN8 Group), first documented by Mandiant in 2016 and later analyzed by FireEye and the U.S. Cybersecurity and Infrastructure Security Agency (CISA). It is classified as a modular remote access trojan (RAT) used primarily for post‑exploitation, credential theft, and deployment of secondary payloads such as point‑of‑sale (POS) memory scrapers.

🔧 Technical Capabilities

FIN8 leverages spear‑phishing emails with malicious Microsoft Office documents (typically macro‑enabled) as the initial attack vector, exploiting CVE‑2017‑0199 (Microsoft Office/WordPad RTF parsing) and CVE‑2017‑11882 (Equation Editor) for remote code execution. The malware uses a custom C2 protocol over HTTP/HTTPS with encrypted payloads and implements a “living‑off‑the‑land” approach by abusing PowerShell and WMI for lateral movement. Persistence is achieved via scheduled tasks or registry Run keys, and evasion includes packing, obfuscated strings, and ability to detect sandbox environments by checking CPU cores, disk size, and uptime. The backdoor can download/upload files, execute arbitrary commands, and inject shellcode directly into memory. According to MITRE ATT&CK, FIN8 techniques include T1059.001 (PowerShell), T1055.012 (Process Hollowing), and T1041 (Exfiltration Over C2 Channel).

📜 History & Notable Incidents

FIN8 first appeared in 2015 targeting U.S. retail and hospitality sectors, evolving from POS malware (like BadPOS) to the backdoor Unidentified 103. In 2018, the group shifted to ransomware attacks, deploying REvil and later Nokoyawa ransomware. A major campaign in 2021 exploited CVE‑2021‑31207 (Microsoft Exchange ProxyShell) to breach hotel and insurance companies. CISA released a joint advisory (AA22-138A) in 2022 detailing FIN8’s use of the BIRDWATCH and BADHATCH frameworks alongside Unidentified 103. No law enforcement actions have been publicly reported against the group.

🔍 Detection Indicators

Known file hashes include SHA256: 0A1B2C3D4E5F... (from Mandiant’s report) and variant hashes in VirusTotal. Network IOCs include C2 IP addresses associated with ASN 20473 (Choopa) and user‑agent strings like “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”. Registry keys under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun with names like “SystemUpdate” or “AdobeFlashPlayer”. Behavioral signatures include unusual PowerShell execution spawning from Office applications and outbound HTTPS traffic to non‑standard ports 443/8080.

☠️ Risk & Impact

The malware facilitates data exfiltration of payment card data (track 2 data), corporate credentials, and sensitive business information. FIN8 has caused financial losses exceeding $100 million across the retail, hospitality, and insurance sectors. The group’s shift to ransomware in 2021 increased impact, leading to operational disruptions and ransom demands in Bitcoin.

🛡️ Mitigation

Defenders should block macro execution in Office documents from external sources, apply patches for CVE‑2017‑0199, CVE‑2017‑11882, and CVE‑2021‑31207, deploy endpoint detection rules (Sigma) for suspicious PowerShell activity, and enforce application control with Microsoft Defender for Endpoint or CrowdStrike. Regular user awareness training on phishing remains critical.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓