NEW: Group Profiler — instant APT intel lookup. Try it →

FIN10

Overview

FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizations.

Naming & attribution

FIN10 is tracked under 1 names across the industry. It uses 11 documented ATT&CK techniques — more than 32% of the 174 groups tracked here. Activity attributed since at least 2013.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
FIN10FireEye iSIGHT Intelligence

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Silence — 8 shared techniques (26% overlap)
  • FIN8 — 8 shared techniques (21% overlap)
  • APT18 China — 4 shared techniques (21% overlap)
  • GALLIUM China — 7 shared techniques (20% overlap)
  • INC Ransom — 6 shared techniques (20% overlap)
  • FIN6 — 8 shared techniques (19% overlap)

TTPs — 11 techniques across 6 tactics

Resource Development

Execution

Persistence

Stealth

Discovery

Lateral Movement

Tools & malware (1)

Empire

Reporting (1)