FIN13

G1016

Threat group.View on attack.mitre.org

About this group

FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.

Techniques used53

Procedure examples53

TechniqueProcedure example
T1003.001
LSASS Memory

FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz.

T1003.002
Security Account Manager

FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine.

T1003.003
NTDS

FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it.

T1005
Data from Local System

FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.

T1016
System Network Configuration Discovery

FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information.

T1016.001
Internet Connection Discovery

FIN13 has used `Ping` and `tracert` for network reconnaissance efforts.

T1021.001
Remote Desktop Protocol

FIN13 has remotely accessed compromised environments via Remote Desktop Services (RDS) for lateral movement.

T1021.002
SMB/Windows Admin Shares

FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers.

T1021.004
SSH

FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement.

T1021.006
Windows Remote Management

FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers.

T1036
Masquerading

FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file.

T1036.004
Masquerade Task or Service

FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory.

T1036.005
Match Legitimate Resource Name or Location

FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war.

T1046
Network Service Discovery

FIN13 has utilized `nmap` for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network.

T1047
Windows Management Instrumentation

FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines.

View all 53 procedure examples

Software4

Campaigns0

None recorded.

References2

  1. Mandiant FIN13 Aug 2022 Open source
    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.
  2. Sygnia Elephant Beetle Jan 2022 Open source
    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.