FIN10

MITRE ATT&CK: G0051 View on attack.mitre.org

Aliases: FIN10

First seen
2013-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:57:11

Targeted industries: energy-and-utilities financial-services professional-services

Targeted regions: country_code:ca country_code:us

Context

FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizations.

Detection coverage

  • 5 YARA rules
  • 398 Sigma rules

Malware & tools used

  • File Deletion (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Local Accounts (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Tool (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • PowerShell (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Empire (malware)

Reports & references

  • Mandiant — Rpt Fin10 (report)
  • MITRE ATT&CK — G0051 (report)
  • services.google.com — Rpt Fin 10 Anatomy Of A Cyber En (report)

External references