FIN12, also tracked as DEV-0237 and Pistachio Tempest, is a financially motivated ransomware deployment group active since at least 2018. The group is widely associated with rapid post-compromise operations, historically centered on Ryuk and later also linked to Conti, Hive, BlackCat/ALPHV, and more recently Qilin in reported related activity. FIN12 is notable for prioritizing speed to encryption over prolonged dwell time or routine data theft, with reporting describing median dwell times of less than two days and average time-to-ransom of roughly four days. FIN12 specializes in post-exploitation and ransomware deployment rather than consistently obtaining its own initial access. It has relied heavily on access provided by other criminal actors, especially TrickBot-associated operators and later BazarLoader/BazarBackdoor-related access providers. The group has also been linked through broader ecosystem reporting to access sourced via brokers such as Exotic Lily. Once inside victim environments, FIN12 has repeatedly used Cobalt Strike Beacon as a primary post-compromise framework and has also used Sliver in intrusions beginning in 2021. Additional tooling reported in FIN12 operations includes Empire, Meterpreter, Anchor, Grunt, SystemBC, and several in-memory droppers such as WeirdLoop, IceCandle, MaltShake, and WhiteDagger; GrimAgent has been assessed as potentially distinctive to the group. Operationally, FIN12 has demonstrated mature enterprise intrusion tradecraft including reconnaissance, credential access, lateral movement, and large-scale ransomware deployment. Reported techniques include use of PsExec, WMIC, PowerShell, RDP, scheduled tasks, Group Policy, WebDAV, and batch-scripted deployment workflows. The group has frequently staged tooling and ransomware deployment materials centrally before pushing payloads across victim networks. Reporting also links DEV-0237 to attacks using Hive against healthcare and software organizations, and to BlackCat affiliate activity involving privilege escalation, network scanning, lateral movement, mass deployment, and use of ExMatter for data exfiltration in double-extortion cases. FIN12 has shown a strong concentration on large enterprises, especially in North America, with a notable and unusual affinity for the healthcare sector. Victims have also expanded into Europe, Asia-Pacific, the Middle East, and Latin America. Most observed victims have been high-revenue organizations. Although FIN12 has generally emphasized fast encryption over multifaceted extortion, at least one Conti-linked intrusion involved theft of victim data and extortion based on stolen information. The actor is assessed to be composed of Russian-speaking cybercriminals likely operating from the Commonwealth of Independent States sphere, and is commonly discussed in relation to the broader TrickBot, Ryuk, and Conti criminal ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group observed using Conti and Ryuk ransomware, with a noted focus on healthcare targets.
Financially motivated threat actor tracked by Microsoft under the Tempest family.
Listed as one of multiple threat groups associated with using SystemBC.
Prolific ransomware affiliate group (per Microsoft) that conducts intrusions and deploys multiple RaaS families, demonstrating affiliate overlap across different ransomware brands.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.