Uptime Hamster: 10d 11h 5mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza FIN10

FIN10

1 incidentes 0 paises 0 sectores apt UNKNOWN Ultimo: 2026-05-25
Aliases: FIN10, G0051, "Casinos, pero sin evidencia directa
Ver en IntelTracker → APTTrail →
FIN10 is a financially motivated cyber extortion group first observed as early as 2013, with activity continuing through at least 2016. The group's primary motivation is the theft of corporate business data and personally identifiable information, which they use to extort victim organizations for financial gain. FIN10 distinguishes itself by exclusively using publicly available software and tools, such as Metasploit, PowerShell Empire, and SplinterRAT, rather than developing custom malware. If ransom demands are not met, the group escalates its tactics by publicly leaking stolen data and, in some cases, deploying destructive batch scripts to delete critical operating system files and shut down systems. FIN10 has attempted to masquerade as various hacktivist groups, including 'Angels_Of_Truth' and 'Tesla Team', though evidence suggests their communications were translated.

Aliases del actor

FIN10G0051"Casinospero sin evidencia directa

Actores similares

sinobiransomware · 274dark-basinactor · 1Password Guessingactor · 1Malvertisingactor · 1Identify Business Tempoactor · 1vanhelsingactor · 1VanHelsingransomware · 1singhealth---shimratactor · 1hellsing-aptactor · 1singing-spideractor · 1
Motivacion