FIN12
Description
(Mandiant) Today, Mandiant Intelligence is releasing a comprehensive report detailing FIN12, an aggressive, financially motivated threat actor behind prolific ransomware attacks since at least October 2018. FIN12 is unique among many tracked ransomware-focused actors today because they do not typically engage in multi-faceted extortion and have disproportionately impacted the healthcare sector. They are also the first FIN actor that we are promoting who specializes in a specific phase of the attack lifecycle—ransomware deployment—while relying on other threat actors for gaining initial access to victims. This specialization reflects the current ransomware ecosystem, which is comprised of various loosely affiliated actors partnering together, but not exclusively with one another.
Names
Name | Name-Giver |
---|---|
FIN12 | Mandiant |
Country
Motivation
- Financial crime
- Financial gain
First Seen
2018
Observed Sectors
Observed Countries
Tools
Information
- https://www.mandiant.com/resources/fin12-ransomware-intrusion-actor-pursuing-healthcare-targets
- https://www.mandiant.com/media/12596/download
Other Information
Uuid
b43cdd5b-3411-4c5f-9190-e8de49a747e1
Last Card Change
2021-11-02