FIN13
[FIN13](https://attack.mitre.org/groups/G1016) is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. [FIN13](https://attack.mitre.org/groups/G1016) achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.(Citation: Mandiant FIN13 Aug 2022)(Citation: Sygnia Elephant Beetle Jan 2022)
Properties
- stix_id
- intrusion-set--fd66436e-4d33-450e-ac4c-f7810f1c85f4
- signal_observed_at
- 2026-09-11T17:55:00+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (50)
Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This inform
An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain. On Win
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, enc
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by use
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries t
Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the dat
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense
Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in fol
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, an
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file s
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own fina
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety o
Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external ad
Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist
Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in nu
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new ac
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users,
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files
Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an adversary has a username a
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of p
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Schedu
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masqueradin
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is don
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The auth
Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain
Software & Tools (5)
[Empire](https://attack.mitre.org/software/S0363) is an open-source, cross-platform remote administration and post-exploitation framework that is publ
[Impacket](https://attack.mitre.org/software/S0357) is an open source collection of modules written in Python for programmatically constructing and ma
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along
[Mimikatz](https://attack.mitre.org/software/S0002) is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along
[certutil](https://attack.mitre.org/software/S0160) is a command-line utility that can be used to obtain certificate authority information and configu
Explore this actor's full graph with Ninja Signal