The FIN11 hacking group that targets organizations around the world with phishing and malware campaigns, which has been active since 2016, has now switched to ransomware attacks, reflecting how profitable ransomware attacks are for hackers.

The campaign has been analyzed by FireEye Mandiant researchers , who describe the hackers as an “established financial crime group” that has carried out some of the longest-running hacking campaigns.
The group began by attacking banks, retailers and restaurants, but has grown to target a wide range of sectors in different regions around the world, sending thousands of phishing emailsandsimultaneously carrying out attacks against multiple organizations at any given time.
For example, in just one week, Mandiant observed simultaneous campaigns targeting pharmaceutical, shipping, and logistics industries in both North America and Europe.
However, despite attacks targeting a wide variety of organizations around the world, many of the original phishing campaigns are still tailored to encourage a victim to download a malicious Microsoft Office that states that macros need to be enabled.
This starts an "infection chain" that creates multiple backdoors on compromised systems, as well as the ability to recover admin credentials and move laterally across networks.
FIN11's campaigns were initially embedded in networks to steal data, with researchers noting that the hacking group typically used BlueSteal, a tool used to steal banking information from Point-of-Sale (POS) terminals.
With finances being the focus of the group, it is possible that FIN11 was selling this information to other cybercriminals on the dark web or simply exploiting the details for its own benefit.
But now FIN11 is using its extensive network as a means of delivering ransomware to compromised networks, with attackers spreading the Clop ransomware and demanding a ransom in bitcoin to restore the network.
Simply put, this change in tactics is all about the group wanting to make as much money – and ransomware has become a quick and easy way for cybercriminals to make money as the variety of targets is wider.
In an attempt to blackmail victims into paying the ransom, some ransomware gangs have used their access to networks to steal sensitive or personal data and threaten to leak it if they don't receive the money they demand for the decryption key – and FIN11 has adopted this as a tactic.
