Auteur Sujet: [FireEye]FIN10: Anatomy of a Cyber Extortion Operation  (Lu 3006 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[FireEye]FIN10: Anatomy of a Cyber Extortion Operation
« le: juin 16, 2017, 14:00:52 »
FIN10: Anatomy of a Cyber Extortion Operation

FireEye has identified a set of financially motivated intrusion
  operations being carried out by an actor we have dubbed FIN10.
  Beginning as early as 2013 and continuing through at least 2016, we
  have observed FIN10 primarily targeting casinos and mining
  organizations in North America, with a focus on Canada.


 

We believe the primary goal of FIN10 is to steal corporate business
  data, files, records, correspondence and customer PII for the purposes
  of extorting victim organizations for the non-release of stolen data.
  The group primarily demands as ransom in Bitcoins that equates to
  anywhere from nearly $125,000 to more than $600,000.


 

Download our report,
    FIN10: Anatomy
      of a Cyber Extortion Operation
, to learn more about FIN10, including:


 
  • The publicly-available software, scripts, and techniques that
        FIN10 primarily relies on to gain a foothold into victims’
      networks.
  • How the threat group posts proof of the stolen data
        on publicly accessible websites.
  • How failure to pay the
        threat group could result in the public release of stolen data and
        potential disruption or destruction of the victim’s information
        assets and systems.

 

Additionally, FireEye provides many tips for dealing and interacting
  with threat actors such as FIN10. Some of these recommendations include:


 
  • Working quickly, staying focused, considering all options and
        potentially involving forensic, legal, law enforcement and public
        relations experts before taking any actions or communicating with
        the threat actor.
  • Ensuring strong segmentation and controls
        over backups so organizations can quickly recover from a
      breach.
  • Focusing on broader security improvements once an
        incident has been resolved, and ensuring the threat actor cannot
        come back in a different way.

 

Although FireEye has observed FIN10 primarily targeting casinos and
  mining organizations in North America (predominately in Canada), all
  organizations from around the world must be prepared to detect and
  respond to threats from this group and other bad actors.


 

Learn more
    about FIN10
and how best to prevent, detect and respond to breaches.


Source: FIN10: Anatomy of a Cyber Extortion Operation

Tags: