Threat actor · all actors
FIN13G1016 state
🇷🇺 RU
aka FIN13, Elephant Beetle, TG2003
Last updated: 2026-08-20
About this actor
Since 2017, Mandiant has been tracking FIN13, an industrious and versatile financially motivated threat actor conducting long-term intrusions in Mexico with an activity timeframe stretching back as early as 2016. Although their operations continue through the present day, in many ways FIN13's intrusions are like a time capsule of traditional financial cybercrime from days past. Instead of today's prevalent smash-and-grab ransomware groups, FIN13 takes their time to gather information to perform fraudulent money transfers. Rather than relying heavily on attack frameworks such as Cobalt Strike, the majority of FIN13 intrusions involve heavy use of custom passive backdoors and tools to lurk in environments for the long haul.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
MandiantFIN financially-motivated
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 75 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.002Security Account Manager ↗T1003.003NTDS ↗T1005Data from Local System ↗T1016System Network Configuration Discovery ↗T1016.001Internet Connection Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.002SMB/Windows Admin Shares ↗T1021.004SSH ↗T1021.006Windows Remote Management ↗T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1036.005Match Legitimate Resource Name or Location ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1056Input Capture ↗T1056.001Keylogging ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1069Permission Groups Discovery ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.001Default Accounts ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1090Proxy ↗T1090.001Internal Proxy ↗T1098Account Manipulation ↗T1098.007Additional Local or Domain Groups ↗T1105Ingress Tool Transfer ↗T1133External Remote Services ↗T1134Access Token Manipulation ↗T1134.003Make and Impersonate Token ↗T1135Network Share Discovery ↗T1136Create Account ↗T1136.001Local Account ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1550Use Alternate Authentication Material ↗T1550.002Pass the Hash ↗T1552Unsecured Credentials ↗T1552.001Credentials In Files ↗T1556Modify Authentication Process ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1564Hide Artifacts ↗T1564.001Hidden Files and Directories ↗T1565Data Manipulation ↗T1572Protocol Tunneling ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1589Gather Victim Identity Information ↗T1590Gather Victim Network Information ↗T1590.004Network Topology ↗T1657Financial Theft ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 47 / 75 | 63% |
SI-4 | 47 / 75 | 63% |
AC-3 | 38 / 75 | 51% |
AC-6 | 38 / 75 | 51% |
AC-2 | 37 / 75 | 49% |
CM-2 | 36 / 75 | 48% |
CM-7 | 35 / 75 | 47% |
AC-5 | 32 / 75 | 43% |
IA-2 | 30 / 75 | 40% |
CM-5 | 28 / 75 | 37% |
CA-7 | 24 / 75 | 32% |
SI-3 | 24 / 75 | 32% |
AC-4 | 21 / 75 | 28% |
RA-5 | 21 / 75 | 28% |
SC-7 | 20 / 75 | 27% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Operation Wocao 0.37
- APT39 0.36
- APT3 0.36
- Operation CuckooBees 0.35
- GALLIUM 0.35
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00