FIN10 is a financially motivated threat actor targeting organizations primarily in North America.
Analyst brief
FIN10 is a financially motivated threat actor targeting organizations primarily in North America, especially Canada. After gaining access, they exfiltrate sensitive data for extortion purposes, and if the demand is unmet, they destroy production Windows systems by deleting critical OS files. The actor leverages tools like Empire and uses TTPs such as Scheduled Task and Registry Run Keys for persistence, along with RDP for lateral movement. Defenders should monitor for anomalous RDP connections, unusual scheduled task creation, registry run key modifications, and file deletion activities, focusing on early detection of extortion-related behavior.
FIN10
G0051
unknown
FireEye has observed multiple targeted intrusions occurring in North America — predominately in Canada — dating back to at least 2013 and continuing through at least 2016, in which the attacker(s) have compromised organizations’ networks and sought to monetize this illicit access by exfiltrating sensitive data and extorting victim organizations. In some cases, when the extortion demand was not met, the attacker(s) destroyed production Windows systems by deleting critical operating system files and then shutting down the impacted systems. Based on near parallel TTPs used by the attacker(s) across these targeted intrusions, we believe these clusters of activity are linked to a single, previously unobserved actor or group that we have dubbed FIN10.