FIN10 is a threat actor with documented targeting in Canada and the United States. Its operations rely on publicly available software to establish footholds, maintain persistence, and conduct post-compromise activity in victim networks. FIN10 has used stolen credentials to access remote networks through VPN services protected by single-factor authentication and has used Remote Desktop Protocol for lateral movement. FIN10 uses PowerShell and Windows batch scripts for malicious command execution. Its persistence mechanisms include Service for User (S4U) scheduled tasks, PowerShell Empire's scheduled-task functionality, and Registry-based autostart persistence. After moving laterally, the actor has deployed Meterpreter stagers and SplinterRAT instances on additional systems. It has also used Meterpreter to enumerate users on remote systems. Documented destructive activity includes using batch scripts and scheduled tasks to delete critical system files.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an annotated actor associated with the detection technique.
Referenced solely as an ATT&CK-associated group for Windows built-in account renaming/local-account abuse; no campaign or activity is described.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.