Also known as: Elephant Beetle, TG2003
FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.(Citation: Mandiant FIN13 Aug 2022)(Citation: Sygnia Elephant Beetle Jan 2022)
Executive Summary
FIN13, also known as Elephant Beetle or TG2003, is a financially motivated cyber threat group targeting the financial, retail, and hospitality sectors in Mexico and Latin America since at least 2016. The group specializes in stealing intellectual property, financial data, mergers and acquisition information, and personally identifiable information (PII). FIN13 exhibits advanced technical capabilities, leveraging a range of MITRE ATT&CK techniques to compromise systems and exfiltrate sensitive data.
Goals & Targeting
FIN13's strategic objectives appear to be primarily financial, targeting sectors with high-value data such as financial transactions, intellectual property, and merger information. The group's focus on Mexico and Latin America suggests a regional emphasis for targeting, potentially due to weaker cybersecurity measures or lucrative industries in these regions. FIN13 achieves its goals by compromising systems to exfiltrate sensitive data, which is likely sold or exploited for monetary gain.
Enhanced Description
FIN13 is a financially motivated cyber threat group that has been active since at least 2016. The group primarily targets the financial, retail, and hospitality sectors in Mexico and Latin America, focusing on stealing intellectual property, financial data, mergers and acquisition information, and personally identifiable information (PII). FIN13's activities have been documented by Mandiant and Sygnia, with evidence of its operations as early as 2016. The group demonstrates a high level of technical sophistication, utilizing a variety of tactics such as web shell creation, credential dumping via LSASS memory, and pass-the-hash techniques. These actions suggest that FIN13 is capable of conducting prolonged campaigns to gather and monetize sensitive information. Despite its known activities, there are limited details on specific campaigns or the exact tools used, which hinders a comprehensive understanding of its full operational scope.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
FIN13's activities suggest a long-term presence in targeted regions, with operations spanning multiple years. While specific campaigns remain un detailed, the group's use of advanced techniques indicates a capability for sustained and stealthy campaigns. The targeting of financial data suggests that FIN13 may be linked to organized crime or financial fraud networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in FIN13's financial motivations and targeting sectors, based on Mandiant and Sygnia reports. Limited details on exact tools used or specific campaigns, which introduces some uncertainty regarding its full capabilities.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
53
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
13
Tactics