#FIN6

2025-06-15

📢 Skeleton Spider : Livraison de malware via le cloud
📝 L'article de SecuritySnacks, publié le 10 juin 2025, met en lumière les activités du groupe de cybercriminalité FIN6, également connu sous le nom de **Skeleton Spider**...
📖 cyberveille : cyberveille.ch/posts/2025-06-1
🌐 source : dti.domaintools.com/skeleton-s
#FIN6 #IOC #Cyberveille

2025-06-13

ICYMI: DomainTools Investigations released new research this week!

Skeleton Spider (aka FIN6) is leveraging trusted cloud services like AWS to deliver malware through fake job applications and resume-themed phishing campaigns.

🔍 Learn how this financially motivated group is:

🔹Exploiting cloud infrastructure to evade detection
🔹Using social engineering to lure victims
🔹Building resilient, scalable malware delivery systems

Read the full analysis here: dti.domaintools.com/skeleton-s

#CyberSecurity #ThreatIntelligence #Malware #CloudSecurity #Phishing #FIN6 #SkeletonSpider #InfoSec

2025-06-10

Recruiters, take note: FIN6 hackers are now posing as job seekers, using fake resumes and slick online profiles to breach security. Ever wondered how real-life trust can turn into a cyber trap?

thedefendopsdiaries.com/fin6s-

#fin6
#phishing
#cybersecurity
#socialengineering
#recruitmentsecurity

2025-06-10

Cybercrime group FIN6 (aka Skeleton Spider) is leveraging trusted cloud services like AWS to deliver malware through fake job applications.

Our latest analysis breaks down:
🔹 How attackers use LinkedIn & Indeed to build trust
🔹 The use of resume-themed phishing lures
🔹 Cloud-hosted infrastructure that evades detection
🔹 The delivery of the More_eggs backdoor via .LNK files
🔹 Key defense strategies for recruiters and security teams

This campaign is a masterclass in low-complexity, high-evasion phishing

📖 Read the full breakdown: dti.domaintools.com/skeleton-s

#CyberSecurity #ThreatIntel #FIN6 #Phishing #CloudSecurity #MalwareAnalysis #InfoSec #SkeletonSpider

Selena Larsonselenalarson
2023-12-12

Speaking of sharing research.. I’m stoked to publish on this recently observed activity by (overlaps with ). We saw them targeting recruiters directly via email and using some really fun social engineering techniques. They always deliver More_eggs malware proofpoint.com/us/blog/threat-

2022-12-01

There hasn't been much reporting on #FIN6 lately but they have been active... not sure about successful but they have been active 😂​

2022-11-11

#FIN6 just can’t stay away from holiday shopping season. This 2019 article from IBM X-Force IRIS is a good recap of TTPs still very much in use today.
securityintelligence.com/posts

2020-09-16

MITRE представила план имитации атак хакерской группы FIN6 #MITRE, #FIN6, #APT securitylab.ru/news/512145.php twitter.com/SecurityLabnews/st

2020-04-07

FIN6 and TrickBot Combine Forces in ‘Anchor’ Attacks - FIN6 fingerprints were spotted in recent cyberattacks that initially infected victims with the Tri... more: threatpost.com/fin6-and-trickb #anchormalware #terraloader #cybercrime #powershell #more_eggs #trickbot #malware #trojan #hacks #fin6

2019-09-02

FIN6 Switches Up PoS Tactics to Target E-Commerce - The group is using the More_eggs JScript backdoor to anchor its attack. more: threatpost.com/fin6-target-eco #vulnerabilities #briackandmortar #creditcarddata #codeinjection #shoppingcart #websecurity #cardskimmer #pointofsale #e-commerce #more_eggs #backdoor #malware #itg08 #fin6

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst