FIN12, also tracked as Pistachio Tempest and formerly DEV-0237, is a financially motivated cybercriminal group active since at least October 2018. It specializes in post-compromise ransomware deployment and operates as a ransomware-as-a-service affiliate, switching payloads across operations. Historically associated primarily with Ryuk, it has also deployed Conti, Hive, and BlackCat/ALPHV and experimented with Agenda ransomware in June 2022. FIN12 targets large, high-revenue organizations, with a notable concentration in healthcare and additional confirmed targeting of software organizations. Its historical victim base was predominantly in the United States and Canada, with subsequent expansion into Europe, Asia-Pacific, the Middle East, and South America. Most identified victims in its early operational profile had annual revenues exceeding $300 million. The group continued targeting healthcare organizations during the COVID-19 pandemic. FIN12 relies heavily on partners and initial-access brokers, including actors associated with TrickBot and BazarLoader. Cobalt Strike Beacon became its dominant post-exploitation framework in early 2020, and it incorporated Sliver into intrusions beginning in 2021. Other tooling includes Empire, Meterpreter, in-memory payload droppers, and SystemBC for proxying connections within compromised environments. It uses PsExec, WMI, PowerShell, RDP, Group Policy, and scheduled tasks to distribute and execute ransomware across victim networks, and has obscured command-and-control infrastructure through Cloudflare and bulletproof hosting. The group prioritizes rapid encryption over routine data theft. Historically observed operations without data theft averaged approximately 2.5 days to ransomware deployment, compared with approximately 12.4 days when data theft occurred. Although exfiltration has been uncommon in its historical intrusions, confirmed Conti activity combined encryption with extortion over stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
24 malware families attributed to this actor across reporting.
19 additional families tracked in Mallory.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group observed using Conti and Ryuk ransomware, with a noted focus on healthcare targets.
Mentioned only in connection with SliverC2 usage in separate operations.
Ransomware affiliate known to use Conti and BlackCat. Its experimentation with Agenda in June 2022 is presented as evidence of a possible, rather than confirmed, Qilin affiliate relationship.
Financially motivated threat actor tracked by Microsoft under the Tempest family.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.