FIN13, also tracked as Elephant Beetle, is a financially motivated intrusion set associated with long-dwell fraud operations targeting finance and commerce organizations, particularly in Latin America. Reporting has linked the cluster strongly to Spanish-speaking Latin America, especially Mexico, based on victimology, tooling characteristics, and operational artifacts. The group is known for patience, stealth, and extensive use of legitimate administration features, publicly available tools, and custom scripts rather than reliance on novel malware alone. FIN13 has primarily targeted enterprise environments that support payment processing and financial operations, with the objective of stealing credentials, point-of-sale data, ATM-related data, and ultimately enabling fraudulent financial transactions. The actor has been observed compromising Java-based web application infrastructure, especially legacy deployments on Linux servers, including IBM WebSphere and Oracle WebLogic, and then maintaining access through web shells, malicious application deployments, and follow-on credential abuse. Tradecraft attributed to FIN13 includes exploitation of public-facing applications and abuse of default credentials for initial access; deployment of web shells and malicious server-side components for persistence and command execution; use of Registry Run keys for Windows persistence; and creation of hidden files and directories on Linux and Windows systems to conceal tooling and collected data. The group has used HTTP for command and control and for chaining web shells prior to exfiltration. Post-compromise activity includes extensive host and network reconnaissance. FIN13 has used native commands and scripts to collect system information, enumerate files and directories, discover network configuration, and identify domain accounts associated with Service Principal Names. It has also leveraged PowerShell, Windows Management Instrumentation, Windows command shell, and SQL Server command execution features for execution, lateral movement, and internal expansion. Observed tooling includes credential theft and privilege escalation utilities, network scanning tools, and frameworks commonly used for remote administration and post-exploitation. The actor has demonstrated a strong focus on web application servers and Microsoft SQL Server environments, moving laterally through web tiers and database systems, harvesting credentials from local files and configuration stores, and staging sensitive data before exfiltration. FIN13 has also used utilities such as certutil to decode encoded malware components and has relied on compromised enterprise management platforms and administrative accounts to retrieve host and network information. FIN13 is best understood as a financially driven threat actor specializing in long-term, low-noise intrusions that blend into normal enterprise and financial workflows. Elephant Beetle is widely regarded as overlapping with or closely resembling FIN13, and the two names are commonly treated as referring to the same threat cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 malware families attributed to this actor across reporting.
14 additional families tracked in Mallory.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
SAP NetWeaver Invoker Servlet Exploit (CVE-2010-5326) The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a Detour attack.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
FIN13 has used IISCrack.dll as a side-loading technique to load a malicious version of httpodbc.dll on old IIS Servers (CVE-2001-0507).
FIN13 has exploited known vulnerabilities such as ... CVE-2015-7450 (WebSphere Application Server SOAP Deserialization Exploit) ... to gain initial access.
FIN13 has exploited known vulnerabilities such as CVE-2017-1000486 (Primefaces Application Expression Language Injection) ... to gain initial access.
8 more CVEs tied to this actor tracked in Mallory.
127 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in annotations associated with the credential-access technique.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.