Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ FIN13

🌐FIN13

🌐 FIN13 is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: Unknown. We map 14 detection use cases to this actor across 53 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.

View full actor card → All threat actors MITRE ATT&CK group spec (G1016) ↗
14Use cases
0Articles
53Techniques
0IOCs

About this actor (MITRE)

[FIN13](https://attack.mitre.org/groups/G1016) is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. [FIN13](https://attack.mitre.org/groups/G1016) achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.(Citation: Mandiant FIN13 Aug 2022)(Citation: Sygnia Elephant Beetle Jan 2022)

Known aliases

FIN13Elephant Beetle

Top techniques

All other tracked techniques

T1005 · Data from Local SystemT1016 · System Network Configuration DiscoveryT1016.001 · Internet Connection DiscoveryT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1021.004 · SSHT1021.006 · Windows Remote ManagementT1036 · MasqueradingT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1056.001 · KeyloggingT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1069 · Permission Groups DiscoveryT1071.001 · Web ProtocolsT1074.001 · Local Data StagingT1078.001 · Default AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087 · Account DiscoveryT1087.002 · Domain AccountT1090.001 · Internal ProxyT1098.007 · Additional Local or Domain GroupsT1105 · Ingress Tool TransferT1133 · External Remote ServicesT1134.003 · Make and Impersonate TokenT1135 · Network Share DiscoveryT1136.001 · Local AccountT1140 · Deobfuscate/Decode Files or InformationT1190 · Exploit Public-Facing ApplicationT1505.003 · Web ShellT1547.001 · Registry Run Keys / Startup FolderT1550.002 · Pass the HashT1552.001 · Credentials In FilesT1556 · Modify Authentication ProcessT1560.001 · Archive via UtilityT1564.001 · Hidden Files and DirectoriesT1565 · Data ManipulationT1572 · Protocol TunnelingT1574.001 · DLLT1587.001 · MalwareT1588.002 · ToolT1589 · Gather Victim Identity InformationT1590.004 · Network TopologyT1657 · Financial Theft

Detection use cases (14)

FIN13 / Elephant Beetle: Java app-server (WebSphere/WebLogic/JBoss/Tomcat) or IIS spawning OS recon/admin binaries — web-shell command execu AI · profile SΣ FIN13 long-dwell SSH reverse-tunnel / port-forwarding via plink, ssh.exe or PuTTY (T1572) AI · profile SΣ Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules MITRE match Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access MITRE match