
The criminal cyberteam FIN6, which until now specialized in hacking POS (Point of Sale) systems and stealing information from the cards of customers of various stores, seems to have decided to change tactics.
The group, which is known for its attacks on security systems, has now turned its attention to hacking and distributing ransomware across networks.
FireEye was the first to identify and publish a report, in the spring of 2016, about the group's extensive attacks and advanced "arsenal".
At the time, FIN6 had developed a versatile POS malware strain called Trinity (also known as FrameworkPOS). The group could infiltrate large retail store networks, move laterally through their systems, and install Trinity on computers handling POS data in order to extract payment card details that they would later upload to their own servers.
The group then sold the stolen card details on hacking forums, earning millions of dollars.
However, on Friday, FireEye published a new report stating that the group has now turned to deploying ransomware on some of the networks that do not handle POS data. The ransomware it is deploying is a strain of Ryuk and LockerGoga.
Both of these strains belong to the most dangerous and destructive ransomware, which have affected government organizations and large companies, with the most recent victim being Norsk Hydro.
According to previous reports from CrowdStrike, FireEye, Kryptos Logic, McAfee, IBM and Cybereason, the group is believed to operate out of Russia, from where it rents the infrastructure of other groups (Emotet and TrickBot) to seek out large companies and later infect them with Trinity, Ryuk or LockerGoga.
Despite the group's change in tactics, however, analysts are unable to determine whether this is now its main operational function or whether it is a side activity carried out by certain members of the group.
Companies and organizations should be cautious and constantly vigilant for any sign that may indicate they have been infected by this dangerous ransomware.
