Cyber Resilience

Threat actor · all actors

FIN13G1016 state

🇷🇺 RU

aka FIN13, Elephant Beetle, TG2003

Last updated: 2026-08-20

0attributed CVEs
75ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

Since 2017, Mandiant has been tracking FIN13, an industrious and versatile financially motivated threat actor conducting long-term intrusions in Mexico with an activity timeframe stretching back as early as 2016. Although their operations continue through the present day, in many ways FIN13's intrusions are like a time capsule of traditional financial cybercrime from days past. Instead of today's prevalent smash-and-grab ransomware groups, FIN13 takes their time to gather information to perform fraudulent money transfers. Rather than relying heavily on attack frameworks such as Cobalt Strike, the majority of FIN13 intrusions involve heavy use of custom passive backdoors and tools to lurk in environments for the long haul.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G1016

MandiantFIN financially-motivated

FIN13

Unclassifiedno scheme matched

Elephant BeetleTG2003

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 75 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
CM-647 / 7563%
SI-447 / 7563%
AC-338 / 7551%
AC-638 / 7551%
AC-237 / 7549%
CM-236 / 7548%
CM-735 / 7547%
AC-532 / 7543%
IA-230 / 7540%
CM-528 / 7537%
CA-724 / 7532%
SI-324 / 7532%
AC-421 / 7528%
RA-521 / 7528%
SC-720 / 7527%

Co-occurring actors

None.

Similar actors

Similar TTPs