FIN 12: Un groupe cybercriminel aux multiples rançongiciels
ID: 3c202edc-6713-4fb8-ab28-a70435c672bd
STIX ID: report--3c202edc-6713-4fb8-ab28-a70435c672bd
Threat Score
78/100
Uploaded: 2026-07-30
Published Date: 2026-07-30
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:A1
...
...
ANSSI reports on a March 2023 compromise of a CHU Brest server attributed to the FIN12 mode-of-operation (aka PISTACHE TEMPEST), describing initial access via exposed remote desktop using valid credentials, deployment of SystemBC and Cobalt Strike, attempts at privilege escalation and credential harvesting (Mimikatz, SharpRoast, AccountRestore), exploitation artifacts for multiple CVEs, and a catalog of IOCs and Malleable C2 configuration; ANSSI links this incident to a broader series of ransomware campaigns (Ryuk, Conti, Hive, Play, Royal, Nokoyawa) active since 2019 and provides TTP and infrastructure correlations.
