G0051

FIN10FIN10

Also known as: G0051 · FIN10

Known aliases
2

Profile

FireEye has observed multiple targeted intrusions occurring in North America — predominately in Canada — dating back to at least 2013 and continuing through at least 2016, in which the attacker(s) have compromised organizations’ networks and sought to monetize this illicit access by exfiltrating sensitive data and extorting victim organizations. In some cases, when the extortion demand was not met, the attacker(s) destroyed production Windows systems by deleting critical operating system files and then shutting down the impacted systems. Based on near parallel TTPs used by the attacker(s) across these targeted intrusions, we believe these clusters of activity are linked to a single, previously unobserved actor or group that we have dubbed FIN10.

Aliases· 2

FIN10
G0051

MITRE ATT&CK Group crosswalk

G0051

References

  1. https://www2.fireeye.com/rs/848-DID-242/images/rpt-fin10.pdf
  2. https://attack.mitre.org/groups/G0051/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
FIN11
Actor
FIN1
Group
FIN13
Actor
FIN5
Actor
FIN8
Group
FIN4
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.