ITG08
SKELETON SPIDER
MAGECART GROUP 6
Threat IntelligenceAPTJanuary 8, 202615 min read

FIN6: Threat Intelligence Profile

Financially motivated threat group specializing in payment card theft from POS systems and e-commerce platforms, responsible for millions of stolen card numbers across retail and hospitality.

Scroll

FIN6 / ITG08 (also known as ITG08, Skeleton Spider, Magecart Group 6) is a state-sponsored advanced persistent threat group attributed to eCrime (Russian-speaking), active since 2015. The group primarily targets retail, hospitality, POS systems, e-commerce sectors. It is tracked by MITRE ATT&CK as G0037.

Overview & Attribution

Financially motivated threat group specializing in payment card theft from POS systems and e-commerce platforms, responsible for millions of stolen card numbers across retail and hospitality.

Threat Assessment

FIN6 has been active since 2015, attributed to eCrime (Russian-speaking). The group is known for targeting retail, hospitality, POS systems, e-commerce using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

FIN6 employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on retail, hospitality, POS systems, e-commerce sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

FIN6 is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1078 Valid AccountsStolen/purchased credentials
ExecutionT1059.001 PowerShellPowerShell post-exploitation
PersistenceT1053.005 Scheduled TaskScheduled task persistence
CollectionT1005 Data from Local SystemPOS memory scraping
Lateral MovementT1021.002 SMB/Admin SharesSMB lateral movement
ExfiltrationT1041 Exfil Over C2Card data exfiltration

Notable Campaigns

FIN6 has been linked to multiple significant campaigns targeting retail, hospitality, POS systems, e-commerce organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against FIN6

Mjolnir Security provides specialized capabilities to detect and respond to FIN6 operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for FIN6 TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of FIN6 campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: January 8, 2026