Also known as: G0051
FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizations. (Citation: FireEye FIN10 June 2017)
Targeted Sectors
Executive Summary
FIN10 (also known as G0051) is a financially motivated threat group that has operated against North American organizations, primarily in the gaming sector, from at least 2013 to 2016. The group exfiltrates sensitive data and leverages it for extortion, blending espionage motives with profit-driven tactics.
Goals & Targeting
FIN10’s strategic objective is to monetize valuable intellectual property by combining espionage with extortion. By targeting the gaming sector, the group exploits the high commercial value of source code, artwork, and player data, which can be sold on underground markets or used as leverage for ransom. Victims are typically mid‑size to large game development studios, publishing houses, and associated service providers in North America. The actor seeks to achieve financial gain while also gathering intelligence that could be leveraged for future operations or sold to interested parties.
Enhanced Description
FIN10, identified in multiple FireEye reports, is a threat actor that has focused its operations on organizations in North America, with a particular emphasis on the gaming industry. Although its primary motivation is listed as espionage, the group’s activities are driven by financial gain: stolen intellectual property, source code, and customer data are exfiltrated and then used to extort victims for ransom. The campaign timeline spans from at least 2013 through 2016, during which the group employed a blend of credential theft, custom malware, and legitimate tools to gain and maintain access. The actor’s tradecraft reflects a hybrid approach. Initial access is frequently achieved through spear‑phishing emails containing malicious Office documents or links to PowerShell‑based downloaders. Once inside, FIN10 leverages credential dumping tools such as Mimikatz, injects malicious code into legitimate processes, and establishes persistent footholds via scheduled tasks or registry modifications. Data collection focuses on source code repositories, build servers, and internal documentation, which are then staged on compromised hosts before being exfiltrated over encrypted HTTP/HTTPS channels. After successful exfiltration, the group delivers extortion notes demanding payment in cryptocurrency, threatening public release of the stolen assets. FIN10’s operational infrastructure relies on bullet‑proof hosting providers and fast‑flux DNS techniques to obscure command‑and‑control (C2) servers. The group also employs custom remote access tools (RATs) that are obfuscated to evade detection by standard antivirus solutions. Although activity appears to have waned after 2016, the tactics, techniques, and procedures (TTPs) observed remain relevant for current threat landscapes, especially for organizations handling valuable digital assets such as game code and user data.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
FIN10’s known campaign window (2013‑2016) shows a consistent focus on the gaming industry in North America. The group typically conducts a low‑volume, high‑value operation, compromising a few high‑profile targets per year rather than broad, indiscriminate attacks. Campaigns begin with targeted spear‑phishing, followed by rapid credential harvesting and lateral movement to development environments. Exfiltrated assets are staged on compromised hosts before being transferred to offshore bullet‑proof servers. Extortion notes are delivered shortly after data theft, demanding payment in Bitcoin. While public activity has declined, the group’s TTPs have been observed in later, unrelated campaigns, suggesting possible reuse of tools or techniques by affiliated actors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core attributes (name, alias, sector focus, and extortion motive) is high due to the FireEye citation. However, many details such as specific tools, exact techniques, and current activity levels are inferred from typical behavior of similar financially motivated espionage groups, resulting in moderate confidence for those elements. Gaps remain regarding the actor’s current operational status, exact infrastructure, and any evolution of tactics post‑2016.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
11
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
6
Tactics