The FIN4 hacker group carried out more than 100 attacks in 2013, on publicly traded companies (Wallstreet) or consulting firms.
FireEye researchers report in their report that attacks were carried out with the aim of intercepting confidential data: “FIN4 sought to infiltrate the networks of approximately 100 companies, most of which (2/3) are pharmaceutical companies or related to public healthcare. The remaining targets include consulting firms representing public organizations,” the report states, among other things.
How attacks are carried out
For their attacks, hackers use well-crafted spear phishing emails aimed at stealing email credentials (username, password). Access to email accounts of top executives, legal counsel, researchers, external consultants, allows FIN4 to obtain confidential information that could influence stock prices and give a significant advantage in trading.
FireEye experts have found nine C&C servers used by the FIN4 group, which moves stolen data through the Tor network. “FIN4 appears to rely heavily on Tor software, which it uses to connect to victims’ email accounts.
FIN4 does not use any malware to steal user data and passwords. Experts discovered that it uses phishing e-mails, which are particularly attractive to investors and shareholders. Usually the e-mail contains a Microsoft Office document with VBA Macros. Once the user opens the document, an Outlook dialog box pops up, asking for the user's credentials.
Experts also observed that the attackers used access to victims' accounts to manipulate conversations about specific topics. Notably, however, the hackers created special Outlook for the victims' accounts that redirected emails containing words like "malware," "hacked," and "phishing" to the Deleted Items folder, apparently to avoid the victims being notified about the ongoing attacks.

