FIN13, also tracked as Elephant Beetle, is a financially motivated intrusion set associated with long-running fraud operations against organizations in Latin America, particularly in the finance and commerce sectors. The group is known for targeting legacy Java-based enterprise applications on Linux servers, especially IBM WebSphere and Oracle WebLogic, and for abusing vulnerable or poorly secured public-facing applications to gain initial access. Reported tradecraft includes exploitation of known vulnerabilities in enterprise middleware and SAP platforms, abuse of default credentials on web management interfaces, and deployment of malicious WAR archives and web shells to establish footholds. The actor emphasizes stealth, patience, and operational longevity over novel malware. FIN13 has been observed maintaining access for extended periods while studying victims’ business processes, then conducting fraudulent transactions designed to blend into legitimate financial activity. Its operations rely heavily on web shells, tunneling, and living-off-the-land techniques across both Linux and Windows environments. Observed tooling and behavior include hidden files and folders on compromised Linux systems, use of Windows hidden attributes to conceal collected information, DLL side-loading on legacy IIS servers, PowerShell execution, DNS-based command-and-control behavior, and use of HTTP requests to chain web shells and support data theft. FIN13 performs broad post-compromise reconnaissance and credential access. Documented activity includes browsing local files to obtain administrative credentials, collecting host information with native system utilities, enumerating files and directories, conducting network reconnaissance with standard commands, and querying Service Principal Names in Active Directory environments. The group has also leveraged compromised enterprise management consoles and accounts to retrieve host and network information. Persistence has included Windows Registry Run keys, while lateral movement has involved movement through web application servers and SQL servers using SMB, WMI, database command execution, web-shell tunneling, and custom proxying or port-forwarding utilities. The actor has also targeted internal Microsoft SQL Server environments, using SQL-focused web shells and administrative tooling, attempting to obtain password material, and creating privileged database accounts for persistence. Additional observed capabilities include use of credential dumping and token abuse tooling, data staging and compression, and exfiltration over web protocols. FIN13 is widely assessed as closely aligned with, or overlapping, the activity cluster tracked as Elephant Beetle, with reporting indicating strong ties to Spanish-speaking Latin America, especially Mexico.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
SAP NetWeaver Invoker Servlet Exploit (CVE-2010-5326) The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a Detour attack.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
FIN13 has used IISCrack.dll as a side-loading technique to load a malicious version of httpodbc.dll on old IIS Servers (CVE-2001-0507).
FIN13 has exploited known vulnerabilities such as ... CVE-2015-7450 (WebSphere Application Server SOAP Deserialization Exploit) ... to gain initial access.
FIN13 has exploited known vulnerabilities such as CVE-2017-1000486 (Primefaces Application Expression Language Injection) ... to gain initial access.
8 more CVEs tied to this actor tracked in Mallory.
127 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed only in detection annotations as associated with exploiting public-facing applications.
Listed as an example threat actor associated with the detection's ATT&CK annotations for Linux system binary backdooring/masquerading behavior.
Mentioned only as one of many threat actors associated with the Masquerading technique annotation in a Splunk detection entry; no campaign-specific activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.