Skip to content
Every technique
T1657No distinct observable

Financial Theft

ImpactLinux, macOS, Office Suite, SaaS, Windows

Where this stands

A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.

T1657 is an objective, not a mechanism, and every observable in the brief is either defined entirely by a per-site list the brief does not supply or is already owned by another technique. AN1361 (Windows) offers windows/security 4624/4648 and Sysmon EventID 1 to catch 'anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems' — but no field on 4624, 4648 or Sysmon 1 carries whether a session or a process is financial. That judgement lives wholly in the FinanceAppList and HighRiskAccounts knobs, which are the site's own inventory of ERP binaries and treasury accounts; with those lists empty the selection degrades to 'a logon occurred' or 'a process started'. […]

Covered instead by T1115, T1114.003, T1564.008, T1486, T1684.001.

What the technique is

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks. Adversaries may Compromise Accounts to conduct unauthorized transfers of funds. In the case of business email compromise or email fraud, an adversary may utilize Impersonation of a trusted entity. Once the social engineering is successful, victims can be deceived into sending money to financial accounts controlled by an adversary. This creates the potential for multiple victims (i.e., compromised accounts as well as the ultimate monetary loss) in incidents involving financial theft. Extortion by ransomware may occur, for example, when an adversary demands payment from a victim after Data Encrypted for Impact and Exfiltration of data, followed by threatening to leak sensitive data to the public unless payment is made to the adversary. Adversaries may use dedicated leak sites to distribute victim data. […]

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1361

    Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses.

  • AN1362

    Monitor server and endpoint logs for unusual outbound network connections to cryptocurrency nodes, unauthorized scripts accessing financial systems, or automation targeting payment file formats. Detect curl/wget activity aimed at exfiltrating transaction data or credentials from financial apps.

  • AN1363

    Monitor unified logs for access to payment applications, browser plug-ins, or Apple Pay services from non-standard processes. Detect anomalous use of Automator scripts or keychain extraction targeting financial account credentials.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.