logo

FIN10__2017__rpt-fin10.pdf

ID: 9e821cd2-8025-4189-86c0-41a83858839c

STIX ID: report--9e821cd2-8025-4189-86c0-41a83858839c

Threat Score

75/100

Uploaded: 2026-08-14

Published Date: 2017-06-15

Last Modified Date: 2017-06-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye describes FIN10, a financially motivated extortion group active since at least 2013 that targeted North American casinos and mining firms (focus on Canada). The report summarizes initial compromise via spear-phishing, use of Meterpreter/Metasploit, PowerShell Empire and SplinterRAT for persistence and lateral movement, use of RDP/VPN and stolen credentials for access, exfiltration and public posting of stolen data, extortion demands of 100–500 BTC, and destructive batch scripts to delete Windows system files; it also provides mitigation lessons and a sample extortion email.