logo

FIN13__2022__FIN13_A_Cybercriminal_Threat_Actor_Focused_on_Mexico_Mandiant.pdf

ID: 0f40db02-6965-47e9-8ddf-1f14846d997e

STIX ID: report--0f40db02-6965-47e9-8ddf-1f14846d997e

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2022-01-11

Last Modified Date: 2022-01-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FIN13 is a financially motivated cybercriminal actor tracked by Mandiant since ~2016 that exclusively targets Mexican entities (notably financial, retail, and hospitality). The actor favors long, stealthy intrusions using passive backdoors and web shells (e.g., BLUEAGAVE, SWEARJAR, SIXPACK, JSPRAT), performs extensive reconnaissance and credential theft, moves laterally with native tooling and custom utilities, and exfiltrates POS/ATM and treasury data to facilitate fraudulent ISO 8583 transactions; the report includes malware descriptions, MITRE ATT&CK mappings, IOCs, and recommended validation actions.