LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1016: FIN13

FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.[1][2]

EnterpriseG1016GroupObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

FIN13, also known as Elephant Beetle, is a financially motivated group reported by ATT&CK to target financial, retail, and hospitality organizations in Mexico and Latin America, with objectives including theft of intellectual property, financial data, M&A information, and PII. For leaders, the practical issue is not just a named group: the mapped behavior points to credential theft, lateral movement, discovery, persistence, and collection patterns that can turn an intrusion into data-loss and fraud risk.

Executive priority

Prioritize validation of identity, Windows administration, and sensitive-data monitoring controls where the organization operates in or supports Mexico/Latin America, or where financial, retail, hospitality, PII, financial-data, or M&A repositories are material. This object is useful for board and audit discussions because it links business-impact data categories to defensive questions: can the organization prove it monitors credential dumping, remote administration misuse, scheduled-task persistence, and access to high-value data stores?

Technical view

ATT&CK does not provide an official detection section for FIN13, so SOC and IR teams should derive validation from the reported relationships. Coverage should be checked across credential access techniques including LSASS Memory, SAM, and NTDS; lateral movement via RDP, SMB/Windows Admin Shares, SSH, and WinRM; execution through WMI, PowerShell, Windows Command Shell, and Scheduled Task; discovery of network configuration, internet connectivity, services, and connections; and collection from local systems. Tool context includes Mimikatz, certutil, Impacket, and Empire, which means detections should not rely only on malware names but also on behaviors such as credential material access, remote service execution, abnormal administrative protocols, suspicious script execution, and masqueraded services or resources.

Likely telemetry

  • Windows security events and authentication logs for RDP, SMB, WinRM, administrative logons, and domain controller access
  • Endpoint process creation and command-line telemetry for PowerShell, cmd, WMI, schtasks, certutil, Impacket-like activity, and Empire-like post-exploitation behavior
  • Credential-access telemetry around LSASS access, SAM/Registry access, and NTDS.dit access or copying on domain controllers and backups
  • Network telemetry for internal service discovery, port scanning, remote administration protocols, SSH use, and unusual host-to-host connections
  • Task Scheduler and service creation/modification logs, including names that imitate legitimate tasks or services

Detection direction

  • Validate detections by behavior chain, not by group name: discovery followed by credential dumping, administrative protocol use, persistence, and data collection should raise priority.
  • Tune PowerShell, WMI, cmd, scheduled task, and remote administration detections to account for legitimate IT administration; false positives are likely without asset criticality, account role, and change-window context.
  • Pay special attention to domain controllers and backup locations because related techniques include NTDS and SAM/LSASS credential access.
  • Review whether monitoring covers both Windows-heavy behaviors and cross-platform relationships such as SSH and service/network discovery on Linux, macOS, ESXi, network devices, containers, and IaaS where those platforms exist locally.
  • Look for masquerading through task, service, file, registry, or resource names that approximate trusted naming patterns rather than only known malicious filenames.

Mitigation priorities

  • Start with identity hardening: reduce standing administrative privileges, protect domain controllers, enforce strong privileged-access governance, and monitor use of valid accounts for RDP, SMB, SSH, and WinRM.
  • Harden and monitor credential stores, including LSASS protection where applicable, restrictions on credential dumping opportunities, and tight control over access to SAM, NTDS.dit, and backups.
  • Constrain remote administration paths by limiting RDP, SMB admin shares, SSH, WinRM, WMI, and PowerShell to approved administrators, management hosts, and documented use cases.
  • Improve endpoint and server logging for command execution, scheduled tasks, services, and suspicious use of built-in tools such as certutil.
  • Classify and monitor high-value data stores containing PII, financial data, intellectual property, and M&A information so collection activity can be investigated quickly.
Additional notes and limits

This take is based on the supplied ATT&CK group description and relationship context. The strongest business relevance is data theft risk against financial, retail, and hospitality sectors in Mexico and Latin America, plus the related techniques and software indicating credential access, discovery, lateral movement, execution, persistence, stealth, and collection behaviors.

The FIN13 object has no specified platforms, tactics, labels, or official detection guidance. Platform references above come from related ATT&CK techniques and software, not from the group object itself. Local exposure, control effectiveness, and detection coverage require environment-specific evidence.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

FIN13

FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by stealing intellectual property, financial data, mergers and acquisition information, or PII.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

53 rows
DomainIDNameRelationship / procedure
EnterpriseT1587.001MalwareSub-technique

FIN13 has utilized custom malware to maintain persistence in a compromised environment.[1][2]

EnterpriseT1078.001Default AccountsSub-technique

FIN13 has leveraged default credentials for authenticating myWebMethods (WMS) and QLogic web management interface to gain initial access.[2]

EnterpriseT1572Protocol Tunneling

FIN13 has utilized web shells and Java tools for tunneling capabilities to and from compromised assets.[2]

EnterpriseT1021.006Windows Remote ManagementSub-technique

FIN13 has leveraged `WMI` to move laterally within a compromised network via application servers and SQL servers.[2]

EnterpriseT1133External Remote Services

FIN13 has gained access to compromised environments via remote access services such as the corporate virtual private network (VPN).[1]

EnterpriseT1087.002Domain AccountSub-technique

FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`.[1][2]

EnterpriseT1046Network Service Discovery

FIN13 has utilized `nmap` for reconnaissance efforts. FIN13 has also scanned for internal MS-SQL servers in a compromised network.[1][2]

EnterpriseT1505.003Web ShellSub-technique

FIN13 has utilized obfuscated and open-source web shells such as JspSpy, reGeorg, MiniWebCmdShell, and Vonloesch Jsp File Browser 1.2 to enable remote code execution and to execute commands on compromised web server.[2]

EnterpriseT1082System Information Discovery

FIN13 has collected local host information by utilizing Windows commands `systeminfo`, `fsutil`, and `fsinfo`. FIN13 has also utilized a compromised Symantex Altiris console and LanDesk account to retrieve host information.[1][2]

EnterpriseT1016System Network Configuration Discovery

FIN13 has used `nslookup` and `ipconfig` for network reconnaissance efforts. FIN13 has also utilized a compromised Symantec Altiris console and LanDesk account to retrieve network information.[1][2]

EnterpriseT1090.001Internal ProxySub-technique

FIN13 has utilized a proxy tool to communicate between compromised assets.[2]

EnterpriseT1565Data Manipulation

FIN13 has injected fraudulent transactions into compromised networks that mimic legitimate behavior to siphon off incremental amounts of money.[2]

EnterpriseT1059.001PowerShellSub-technique

FIN13 has used PowerShell commands to obtain DNS data from a compromised network.[1]

EnterpriseT1053.005Scheduled TaskSub-technique

FIN13 has created scheduled tasks in the `C:\Windows` directory of the compromised network.[1]

EnterpriseT1136.001Local AccountSub-technique

FIN13 has created MS-SQL local accounts in a compromised network.[2]

EnterpriseT1003.002Security Account ManagerSub-technique

FIN13 has extracted the SAM and SYSTEM registry hives using the `reg.exe` binary for obtaining password hashes from a compromised machine.[2]

EnterpriseT1003.003NTDSSub-technique

FIN13 has harvested the NTDS.DIT file and leveraged the Impacket tool on the compromised domain controller to locally decrypt it.[2]

EnterpriseT1190Exploit Public-Facing Application

FIN13 has exploited known vulnerabilities such as CVE-2017-1000486 (Primefaces Application Expression Language Injection), CVE-2015-7450 (WebSphere Application Server SOAP Deserialization Exploit), CVE-2010-5326 (SAP NewWeaver Invoker Servlet Exploit), and EDB-ID-24963 (SAP NetWeaver ConfigServlet Remote Code Execution) to gain initial access.[1][2]

EnterpriseT1589Gather Victim Identity Information

FIN13 has researched employees to target for social engineering attacks.[1]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

FIN13 has used scheduled tasks names such as `acrotyr` and `AppServicesr` to mimic the same names in a compromised network's `C:\Windows` directory.[1]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers.[2]

EnterpriseT1003.001LSASS MemorySub-technique

FIN13 has obtained memory dumps with ProcDump to parse and extract credentials from a victim's LSASS process memory with Mimikatz.[1][2]

EnterpriseT1564.001Hidden Files and DirectoriesSub-technique

FIN13 has created hidden files and folders within a compromised Linux system `/tmp` directory. FIN13 also has used `attrib.exe` to hide gathered local host information.[1][2]

EnterpriseT1552.001Credentials In FilesSub-technique

FIN13 has obtained administrative credentials by browsing through local files on a compromised machine.[2]

EnterpriseT1657Financial Theft

FIN13 has observed the victim's software and infrastructure over several months to understand the technical process of legitimate financial transactions, prior to attempting to conduct fraudulent transactions.[2]

EnterpriseT1588.002ToolSub-technique

FIN13 has utilized publicly available tools such as Mimikatz, Impacket, PWdump7, ProcDump, Nmap, and Incognito V2 for targeting efforts.[2]

EnterpriseT1134.003Make and Impersonate TokenSub-technique

FIN13 has utilized tools such as Incognito V2 for token manipulation and impersonation.[2]

EnterpriseT1105Ingress Tool Transfer

FIN13 has downloaded additional tools and malware to compromised systems.[1][2]

EnterpriseT1071.001Web ProtocolsSub-technique

FIN13 has used HTTP requests to chain multiple web shells and to contact actor-controlled C2 servers prior to exfiltrating stolen data.[1][2]

EnterpriseT1550.002Pass the HashSub-technique

FIN13 has used the PowerShell utility `Invoke-SMBExec` to execute the pass the hash method for lateral movement within an compromised environment.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

FIN13 has leveraged `xp_cmdshell` and Windows Command Shell to execute commands on a compromised machine. FIN13 has also attempted to leverage the ‘xp_cmdshell’ SQL procedure to execute remote commands on internal MS-SQL servers.[1][2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

FIN13 has used Windows Registry run keys such as, `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\hosts` to maintain persistence.[1]

EnterpriseT1016.001Internet Connection DiscoverySub-technique

FIN13 has used `Ping` and `tracert` for network reconnaissance efforts.[1]

EnterpriseT1036Masquerading

FIN13 has masqueraded staged data by using the Windows certutil utility to generate fake Base64 encoded certificates with the input file.[1][2]

EnterpriseT1059.005Visual BasicSub-technique

FIN13 has used VBS scripts for code execution on comrpomised machines.[2]

EnterpriseT1098.007Additional Local or Domain GroupsSub-technique

FIN13 has assigned newly created accounts the sysadmin role to maintain persistence.[2]

EnterpriseT1574.001DLLSub-technique

FIN13 has used IISCrack.dll as a side-loading technique to load a malicious version of httpodbc.dll on old IIS Servers (CVE-2001-0507).[2]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

FIN13 has remotely accessed compromised environments via Remote Desktop Services (RDS) for lateral movement.[1]

EnterpriseT1590.004Network TopologySub-technique

FIN13 has searched for infrastructure that can provide remote access to an environment for targeting efforts.[1]

EnterpriseT1135Network Share Discovery

FIN13 has executed net view commands for enumeration of open shares on compromised machines.[1][2]

EnterpriseT1560.001Archive via UtilitySub-technique

FIN13 has compressed the dump output of compromised credentials with a 7zip binary.[2]

EnterpriseT1140Deobfuscate/Decode Files or Information

FIN13 has utilized `certutil` to decode base64 encoded versions of custom malware.[1]

EnterpriseT1556Modify Authentication Process

FIN13 has replaced legitimate KeePass binaries with trojanized versions to collect passwords from numerous applications.[1]

EnterpriseT1047Windows Management Instrumentation

FIN13 has utilized `WMI` to execute commands and move laterally on compromised Windows machines.[1][2]

EnterpriseT1021.004SSHSub-technique

FIN13 has remotely accessed compromised environments via secure shell (SSH) for lateral movement.[1]

EnterpriseT1074.001Local Data StagingSub-technique

FIN13 has utilized the following temporary folders on compromised Windows and Linux systems for their operations prior to exfiltration: `C:\Windows\Temp` and `/tmp`.[1][2]

EnterpriseT1056.001KeyloggingSub-technique

FIN13 has logged the keystrokes of victims to escalate privileges.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war.[2]

EnterpriseT1049System Network Connections Discovery

FIN13 has used `netstat` and other net commands for network reconnaissance efforts.[1]

EnterpriseT1083File and Directory Discovery

FIN13 has used the Windows `dir` command to enumerate files and directories in a victim's network.[1]

EnterpriseT1005Data from Local System

FIN13 has gathered stolen credentials, sensitive data such as point-of-sale (POS), and ATM data from a compromised network before exfiltration.[1][2]

EnterpriseT1069Permission Groups Discovery

FIN13 has enumerated all users and roles from a victim's main treasury system.[1]

EnterpriseT1087Account Discovery

FIN13 has enumerated all users and their roles from a victim's main treasury system.[1]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0363: Empire

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]

LinuxmacOSWindows
ToolEnterprise

S0160: certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
4509347cd8c76c49...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle4509347cd8c7…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  2. [2]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  3. [3]
    Elephant Beetle

    (Citation: Sygnia Elephant Beetle Jan 2022)

  4. [4]
    Elephant Beetle

    (Citation: Sygnia Elephant Beetle Jan 2022)

  5. [5]
    Elephant Beetle

    (Citation: Sygnia Elephant Beetle Jan 2022)

  6. [6]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  7. [7]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  8. [8]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  9. [9]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  10. [10]
    mitre-attackG1016
    Open source URL
  11. [11]
    mitre-attackG1016
    Open source URL
  12. [12]
    mitre-attackG1016
    Open source URL
  13. [13]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  14. [14]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  15. [15]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  16. [16]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  17. [17]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  18. [18]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  19. [19]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  20. [20]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  21. [21]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  22. [22]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  23. [23]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  24. [24]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  25. [25]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  26. [26]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  27. [27]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  28. [28]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  29. [29]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  30. [30]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  31. [31]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  32. [32]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  33. [33]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  34. [34]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  35. [35]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  36. [36]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  37. [37]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  38. [38]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  39. [39]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  40. [40]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  41. [41]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  42. [42]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  43. [43]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  44. [44]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  45. [45]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  46. [46]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  47. [47]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  48. [48]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  49. [49]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  50. [50]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  51. [51]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  52. [52]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  53. [53]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  54. [54]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  55. [55]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  56. [56]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  57. [57]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  58. [58]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  59. [59]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  60. [60]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  61. [61]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  62. [62]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  63. [63]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  64. [64]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  65. [65]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  66. [66]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  67. [67]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  68. [68]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  69. [69]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  70. [70]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  71. [71]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  72. [72]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  73. [73]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  74. [74]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  75. [75]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  76. [76]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  77. [77]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  78. [78]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  79. [79]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  80. [80]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  81. [81]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  82. [82]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  83. [83]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  84. [84]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  85. [85]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  86. [86]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  87. [87]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  88. [88]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  89. [89]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  90. [90]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  91. [91]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  92. [92]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  93. [93]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  94. [94]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  95. [95]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  96. [96]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  97. [97]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  98. [98]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  99. [99]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  100. [100]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  101. [101]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  102. [102]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  103. [103]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  104. [104]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  105. [105]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  106. [106]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  107. [107]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  108. [108]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  109. [109]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  110. [110]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  111. [111]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  112. [112]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  113. [113]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  114. [114]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  115. [115]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  116. [116]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  117. [117]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  118. [118]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  119. [119]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  120. [120]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  121. [121]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  122. [122]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  123. [123]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  124. [124]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  125. [125]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  126. [126]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  127. [127]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  128. [128]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  129. [129]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  130. [130]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  131. [131]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  132. [132]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  133. [133]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  134. [134]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  135. [135]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  136. [136]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  137. [137]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  138. [138]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  139. [139]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  140. [140]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  141. [141]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  142. [142]
    Sygnia Elephant Beetle Jan 2022

    Sygnia Incident Response Team. (2022, January 5). TG2003: ELEPHANT BEETLE UNCOVERING AN ORGANIZED FINANCIAL-THEFT OPERATION. Retrieved February 9, 2023.

    Open source URL
  143. [143]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
  144. [144]
    Mandiant FIN13 Aug 2022

    Ta, V., et al. (2022, August 8). FIN13: A Cybercriminal Threat Actor Focused on Mexico. Retrieved February 9, 2023.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.