{"id":"T1657","name":"Financial Theft","url":"https://attack.mitre.org/techniques/T1657","tactics":["impact"],"platforms":["Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0495","stix_id":"x-mitre-detection-strategy--e767f434-dda3-41fe-a9ea-e7aaae251e61","name":"Detection Strategy for Financial Theft","url":"https://attack.mitre.org/detectionstrategies/DET0495","analytics":[{"id":"AN1361","stix_id":"x-mitre-analytic--f2aef85a-c1ea-4d1a-b359-32692c973cdc","name":"Analytic 1361","description":"Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses.","url":"https://attack.mitre.org/detectionstrategies/DET0495#AN1361","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4624, 4648","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"FinanceAppList","description":"Baseline of finance-related executables or ERP processes to monitor closely."},{"field":"HighRiskAccounts","description":"Accounts belonging to finance, treasury, or executives that should be monitored with higher sensitivity."}],"live":true,"detection_strategies":["DET0495"],"techniques":["T1657"]},{"id":"AN1362","stix_id":"x-mitre-analytic--efdca1e1-5a4a-4039-99ab-1cdb7e50e52c","name":"Analytic 1362","description":"Monitor server and endpoint logs for unusual outbound network connections to cryptocurrency nodes, unauthorized scripts accessing financial systems, or automation targeting payment file formats. Detect curl/wget activity aimed at exfiltrating transaction data or credentials from financial apps.","url":"https://attack.mitre.org/detectionstrategies/DET0495#AN1362","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve: Execution of curl, wget, or custom scripts accessing financial endpoints","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Authentication attempts into finance-related servers from unusual IPs or times","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"KnownFinanceIPs","description":"Whitelisted IPs for finance-related traffic to reduce noise."}],"live":true,"detection_strategies":["DET0495"],"techniques":["T1657"]},{"id":"AN1363","stix_id":"x-mitre-analytic--ce3ebda8-d47e-4730-a1f4-3366d33a98ab","name":"Analytic 1363","description":"Monitor unified logs for access to payment applications, browser plug-ins, or Apple Pay services from non-standard processes. Detect anomalous use of Automator scripts or keychain extraction targeting financial account credentials.","url":"https://attack.mitre.org/detectionstrategies/DET0495#AN1363","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Non-standard processes invoking financial applications or payment APIs","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Anomalous keychain access attempts targeting payment credentials","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"MonitoredApps","description":"Financial or payment applications to explicitly monitor for unauthorized use."}],"live":true,"detection_strategies":["DET0495"],"techniques":["T1657"]},{"id":"AN1364","stix_id":"x-mitre-analytic--3bac57c4-1539-4048-b325-88032c78ed08","name":"Analytic 1364","description":"Monitor SaaS financial systems (e.g., QuickBooks, Workday, SAP S/4HANA cloud) for unauthorized access, rule changes, or mass export of financial data. Detect anomalous transfers initiated via SaaS APIs or new MFA-disabled logins targeting finance apps.","url":"https://attack.mitre.org/detectionstrategies/DET0495#AN1364","platforms":["SaaS"],"log_source_references":[{"name":"saas:finance","channel":"Transaction/Transfer: Unusual or large transactions initiated outside business hours or by unusual accounts","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"saas-finance"}],"mutable_elements":[{"field":"TransactionThreshold","description":"Customizable monetary threshold above which financial transactions should be flagged."}],"live":true,"detection_strategies":["DET0495"],"techniques":["T1657"]},{"id":"AN1365","stix_id":"x-mitre-analytic--03364dc1-4b76-4a30-83cf-ae101b960d8e","name":"Analytic 1365","description":"Monitor email and document management systems for fraudulent invoices, impersonation of vendors, or BEC-style payment redirections. Detect abnormal editing of invoice templates, or emails containing known fraud language combined with attachment delivery.","url":"https://attack.mitre.org/detectionstrategies/DET0495#AN1365","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"MailSend: Outlook messages with suspicious subject/body terms (e.g., urgent payment, wire transfer) targeting finance teams","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"},{"name":"m365:office","channel":"Anomalous editing of invoice or payment document templates","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"m365-office"}],"mutable_elements":[{"field":"FraudTerms","description":"Adjustable keyword list for email and document fraud detection."}],"live":true,"detection_strategies":["DET0495"],"techniques":["T1657"]}],"live":true,"version":"1.0","techniques":["T1657"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}