THREAT_ACTOR · G1016
FIN13
Also known as: FIN13, Elephant Beetle
Profile
FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.
MITRE ATT&CK ↗Techniques
53 ATT&CK techniques attributed to this actor.
T1003.001 LSASS MemoryT1003.002 Security Account ManagerT1003.003 NTDST1005 Data from Local SystemT1016 System Network Configuration DiscoveryT1016.001 Internet Connection DiscoveryT1021.001 Remote Desktop ProtocolT1021.002 SMB/Windows Admin SharesT1021.004 SSHT1021.006 Windows Remote ManagementT1036 MasqueradingT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1056.001 KeyloggingT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1069 Permission Groups DiscoveryT1071.001 Web ProtocolsT1074.001 Local Data StagingT1078.001 Default AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087 Account DiscoveryT1087.002 Domain AccountT1090.001 Internal ProxyT1098.007 Additional Local or Domain GroupsT1105 Ingress Tool TransferT1133 External Remote ServicesT1134.003 Make and Impersonate TokenT1135 Network Share DiscoveryT1136.001 Local AccountT1140 Deobfuscate/Decode Files or InformationT1190 Exploit Public-Facing ApplicationT1505.003 Web ShellT1547.001 Registry Run Keys / Startup FolderT1550.002 Pass the HashT1552.001 Credentials In FilesT1556 Modify Authentication ProcessT1560.001 Archive via UtilityT1564.001 Hidden Files and DirectoriesT1565 Data ManipulationT1572 Protocol TunnelingT1574.001 DLLT1587.001 MalwareT1588.002 ToolT1589 Gather Victim Identity InformationT1590.004 Network TopologyT1657 Financial Theft
Software
4 malware/tools attributed to this actor.
MimikatzcertutilImpacketEmpire
Related corpus activity
10,136 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to FIN13.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 10,136.