FIN10
MITRE ATT&CK: G0051 View on attack.mitre.org
Aliases: FIN10
- First seen
- 2013-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:57:11
Targeted industries: energy-and-utilities financial-services professional-services
Targeted regions: country_code:ca country_code:us
Context
FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizations.
Detection coverage
- 5 YARA rules
- 398 Sigma rules
Malware & tools used
- File Deletion (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Local Accounts (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Scheduled Task (attack-pattern)
- Tool (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- PowerShell (attack-pattern)
- Valid Accounts (attack-pattern)
- Empire (malware)
Reports & references
- Mandiant — Rpt Fin10 (report)
- MITRE ATT&CK — G0051 (report)
- services.google.com — Rpt Fin 10 Anatomy Of A Cyber En (report)