FIN13 is a financially motivated group known for long-term intrusions enabling fraudulent money transfers.
Analyst brief
FIN13 (TG2003, Elephant Beetle) is a financially motivated cybercriminal group active since at least 2016, conducting long-term intrusions primarily in Mexico to enable fraudulent money transfers. They rely on custom passive backdoors and tools like Impacket, Mimikatz, and Empire, employing TTPs such as PowerShell execution and SAM credential dumping. Defenders should focus on detecting exploitation of public-facing applications, unusual PowerShell activity, and protocol tunneling used for stealthy command-and-control.
FIN13
TG2003Elephant Beetle
unknown
Since 2017, Mandiant has been tracking FIN13, an industrious and versatile financially motivated threat actor conducting long-term intrusions in Mexico with an activity timeframe stretching back as early as 2016. Although their operations continue through the present day, in many ways FIN13's intrusions are like a time capsule of traditional financial cybercrime from days past. Instead of today's prevalent smash-and-grab ransomware groups, FIN13 takes their time to gather information to perform fraudulent money transfers. Rather than relying heavily on attack frameworks such as Cobalt Strike, the majority of FIN13 intrusions involve heavy use of custom passive backdoors and tools to lurk in environments for the long haul.
Monitor database and file system access to detect Data Manipulation activities.
FAQ2
What is the primary financial objective of the FIN13 group?+
The group conducts long-term intrusions primarily in Mexico to gather information for fraudulent money transfers.
What are some of the tools and techniques used by FIN13?+
The group relies on custom passive backdoors and tools like Impacket, Mimikatz, and Empire, employing TTPs such as PowerShell execution and SAM credential dumping.