APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
FIN11 (aka Hive0065, ATK103) · APT Atlas
Actors
/
Cybercrime
/
Europe
FIN11
G0092
CRIME
RU · Russia
AKA
Hive0065 · ATK103 · SectorJ04
CrowdStrike
:
GRACEFUL SPIDER
Microsoft
:
Lace Tempest
MITRE
:
G0092
Proofpoint
:
TA505
Targets
25
Sectors
15
Threat types
2
GIRs covered
0/480
Active since
2017
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 3 other aliases
Open Rosetta Stone
CrowdStrike
GRACEFUL SPIDER
Mandiant
FIN11
Microsoft
Lace Tempest
MITRE
G0092
Proofpoint
TA505
UNATTRIBUTED ALIASES
Hive0065
ATK103
SectorJ04
Victimology
Geographic footprint · 25 countries
Region filter
Export
origin · Russia
targeted countries · 25
AMERICAS ·
7
Argentina
·
Bermuda
·
Brazil
·
Chile
·
Colombia
·
Guatemala
·
Mexico
EUROPE ·
13
Austria
·
Belgium
·
Germany
·
Denmark
·
Finland
·
France
·
United Kingdom
·
Hungary
·
Luxembourg
·
Latvia
·
Netherlands
·
Poland
·
Portugal
ASIA ·
5
Israel
·
India
·
South Korea
·
Malaysia
·
Thailand
Sectors targeted
15 of 40
Government
100 actors
Financial Services
74 actors
Pharmaceutical
27 actors
Telecom
72 actors
Retail & Hospitality
33 actors
NGOs & Dissidents
56 actors
Energy / Utilities
59 actors
Education & Research
62 actors
Manufacturing (man)
50 actors
Logistics
22 actors
Hospitality
33 actors
Chemicals
20 actors
Consumer Goods / Electronics
20 actors
Agriculture & Food
18 actors
Maritime
24 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
FIN · Financial Fraud
RAN · Ransomware
MITRE ATT&CK · 22 techniques
Initial Access
· 2
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
Execution
· 6
T1059.001
PowerShell
T1059.003
Credential Access
· 2
T1552.001
Credentials In Files
Impact
· 1
T1486
Data Encrypted for Impact
Command And Control
· 2
T1071.001
Web Protocols
Defense Impairment
· 2
T1112
Modify Registry
Stealth
· 7
T1027.002
Software Packing
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
22 techniques · layer format 4.5
Related actors
By origin and actor type
APT44
nation-state
Russia · 25 targets · since 2009
FIN10
cybercrime
unattributed · 1 targets · since 2013
FIN2
cybercrime
unattributed · 0 targets · since —
FIN6
cybercrime
Russia · 15 targets · since 2014
UNC1543
cybercrime
unattributed · 22 targets · since —
FIN3
cybercrime
unattributed · 1 targets · since —
Windows Command Shell
T1059.005
Visual Basic
T1059.007
JavaScript
T1106
Native API
T1204.001
Malicious Link
T1555.003
Credentials from Web Browsers
T1105
Ingress Tool Transfer
T1685
Disable or Modify Tools
T1027.010
Command Obfuscation
T1055.001
Dynamic-link Library Injection
T1078.002
Domain Accounts
T1140
Deobfuscate/Decode Files or Information
T1218.007
Msiexec
T1218.011
Rundll32