Unidentified 103 (FIN8) is a backdoor malware family attributed to the financially motivated threat group FIN8 (also tracked as Sphinx or FIN8 Group), first documented by Mandiant in 2016 and later analyzed by FireEye and the U.S. Cybersecurity and Infrastructure Security Agency (CISA). It is classified as a modular remote access trojan (RAT) used primarily for post‑exploitation, credential theft, and deployment of secondary payloads such as point‑of‑sale (POS) memory scrapers.
FIN8 leverages spear‑phishing emails with malicious Microsoft Office documents (typically macro‑enabled) as the initial attack vector, exploiting CVE‑2017‑0199 (Microsoft Office/WordPad RTF parsing) and CVE‑2017‑11882 (Equation Editor) for remote code execution. The malware uses a custom C2 protocol over HTTP/HTTPS with encrypted payloads and implements a “living‑off‑the‑land” approach by abusing PowerShell and WMI for lateral movement. Persistence is achieved via scheduled tasks or registry Run keys, and evasion includes packing, obfuscated strings, and ability to detect sandbox environments by checking CPU cores, disk size, and uptime. The backdoor can download/upload files, execute arbitrary commands, and inject shellcode directly into memory. According to MITRE ATT&CK, FIN8 techniques include T1059.001 (PowerShell), T1055.012 (Process Hollowing), and T1041 (Exfiltration Over C2 Channel).
FIN8 first appeared in 2015 targeting U.S. retail and hospitality sectors, evolving from POS malware (like BadPOS) to the backdoor Unidentified 103. In 2018, the group shifted to ransomware attacks, deploying REvil and later Nokoyawa ransomware. A major campaign in 2021 exploited CVE‑2021‑31207 (Microsoft Exchange ProxyShell) to breach hotel and insurance companies. CISA released a joint advisory (AA22-138A) in 2022 detailing FIN8’s use of the BIRDWATCH and BADHATCH frameworks alongside Unidentified 103. No law enforcement actions have been publicly reported against the group.
Known file hashes include SHA256: 0A1B2C3D4E5F... (from Mandiant’s report) and variant hashes in VirusTotal. Network IOCs include C2 IP addresses associated with ASN 20473 (Choopa) and user‑agent strings like “Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)”. Registry keys under HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun with names like “SystemUpdate” or “AdobeFlashPlayer”. Behavioral signatures include unusual PowerShell execution spawning from Office applications and outbound HTTPS traffic to non‑standard ports 443/8080.
The malware facilitates data exfiltration of payment card data (track 2 data), corporate credentials, and sensitive business information. FIN8 has caused financial losses exceeding $100 million across the retail, hospitality, and insurance sectors. The group’s shift to ransomware in 2021 increased impact, leading to operational disruptions and ransom demands in Bitcoin.
Defenders should block macro execution in Office documents from external sources, apply patches for CVE‑2017‑0199, CVE‑2017‑11882, and CVE‑2021‑31207, deploy endpoint detection rules (Sigma) for suspicious PowerShell activity, and enforce application control with Microsoft Defender for Endpoint or CrowdStrike. Regular user awareness training on phishing remains critical.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.