MITRE and its cybersecurity partners have launched a new project that will offer free simulations of the largest hacking groups in the threat landscape today, in order to help educate security teams so they can protect their networks from potential attacks. It is a project of MITRE Engenuity's Center for Threat-Informed Defense and is called the “Adversary Emulation Library”. The project aims to provide free downloadable attack simulation programs. The simulation programs are a collection of step-by-step guides, scripts, and commands that describe and execute malicious operations that are commonly observed in the operations of a particular “adversary”.
The goal of a simulation program is to test a network's defenses and see if automated systems or human operators detect attacks before, during, and after they occur.

MITRE’s first Adversary Emulation program targets the hacking group known as “FIN6,” one of the largest cybercrime groups in the world today. FIN6 has been on the threat landscape since 2015, and is best known for targeting companies that operate high-traffic POS payment terminals, compromising internal networks to install POS malware that steals credit card information. The program targeting FIN6 is the first of many that MITRE plans to make freely available in the coming months.
The programs are developed by MITRE and many cybersecurity industry partners who are part of MITRE Engenuity, a non-profit organization currently comprised of 23 organizations from around the world with highly sophisticated security teams.

Microsoft , Fujitsu and AttackIQ are members of MITRE Engenuity and collaborated with the organization on the FIN6 program. Before MITRE Engenuity was created, MITRE had released two other simulation programs – one in 2017 for the Chinese state-run hacking group APT3” and one earlier this year for the Russian state-run hacking group “APT29” “ .
Positive feedback from these two releases inspired MITRE leadership to work on codifying a structure for simulation programs with industry partners, according to a blog post shared this week by Jon Baker, Director of MITRE Corporation.

One little-known fact about the FIN6 group is that it sometimes tries to deploy ransomware on the networks it compromises, along with Magecart -style skimmers . These small details are included in the FIN6 simulation program from MITRE.
Until MITRE Engenuity releases more programs, security teams can take a look at the adversary simulation programs that Scythe over the summer.
