FIN13__2022__FIN13_A_Cybercriminal_Threat_Actor_Focused_on_Mexico_Mandiant.pdf
ID: 0f40db02-6965-47e9-8ddf-1f14846d997e
STIX ID: report--0f40db02-6965-47e9-8ddf-1f14846d997e
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2022-01-11
Last Modified Date: 2022-01-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FIN13 is a financially motivated cybercriminal actor tracked by Mandiant since ~2016 that exclusively targets Mexican entities (notably financial, retail, and hospitality). The actor favors long, stealthy intrusions using passive backdoors and web shells (e.g., BLUEAGAVE, SWEARJAR, SIXPACK, JSPRAT), performs extensive reconnaissance and credential theft, moves laterally with native tooling and custom utilities, and exfiltrates POS/ATM and treasury data to facilitate fraudulent ISO 8583 transactions; the report includes malware descriptions, MITRE ATT&CK mappings, IOCs, and recommended validation actions.
