APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
FIN12 (aka Trickbot Group, Grim Spider) · APT Atlas
Actors
/
Cybercrime
/
Europe
FIN12
G0102
CRIME
RU · Russia
AKA
Trickbot Group · Grim Spider
CrowdStrike
:
Wizard Spider
Microsoft
:
Ilex Vixen
MITRE
:
G0102
Secureworks
:
GOLD BLACKBURN
Targets
25
Sectors
16
Threat types
1
GIRs covered
0/480
Active since
2018
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 2 other aliases
Open Rosetta Stone
CrowdStrike
Wizard Spider
Mandiant
FIN12
Microsoft
Ilex Vixen
MITRE
G0102
Secureworks
GOLD BLACKBURN
UNATTRIBUTED ALIASES
Trickbot Group
Grim Spider
Victimology
Geographic footprint · 25 countries
Region filter
Export
origin · Russia
targeted countries · 25
AMERICAS ·
7
Argentina
·
Bahamas
·
Chile
·
Colombia
·
Dominican Republic
·
Honduras
·
Mexico
EUROPE ·
11
Austria
·
Belgium
·
Germany
·
Denmark
·
France
·
United Kingdom
·
Hungary
·
Luxembourg
·
Netherlands
·
Serbia
·
Sweden
ASIA ·
6
Bangladesh
·
Brunei
·
India
·
South Korea
·
Pakistan
·
Vietnam
AFRICA ·
1
Tunisia
Sectors targeted
16 of 40
Government
100 actors
Defense
72 actors
Financial Services
74 actors
Pharmaceutical
27 actors
Telecom
72 actors
Retail & Hospitality
33 actors
NGOs & Dissidents
56 actors
Energy / Utilities
59 actors
Education & Research
62 actors
Manufacturing (man)
50 actors
Transportation
31 actors
Logistics
22 actors
Hospitality
33 actors
Chemicals
20 actors
Consumer Goods / Electronics
20 actors
Agriculture & Food
18 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
RAN · Ransomware
MITRE ATT&CK · 49 techniques
Initial Access
· 2
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
Execution
· 5
T1047
Windows Management Instrumentation
Persistence
· 3
T1543.003
Windows Service
Credential Access
· 7
T1003.001
LSASS Memory
Discovery
· 4
T1016
System Network Configuration Discovery
Lateral Movement
· 7
T1021
Remote Services
Collection
· 3
T1005
Data from Local System
T1074
Data Staged
Exfiltration
· 3
T1041
Exfiltration Over C2 Channel
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
T1567.002
Exfiltration to Cloud Storage
Impact
· 2
T1489
Service Stop
Command And Control
· 2
T1071.001
Web Protocols
Defense Impairment
· 2
T1112
Modify Registry
Stealth
· 9
T1027.010
Command Obfuscation
T1036.004
Masquerade Task or Service
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
49 techniques · layer format 4.5
Related actors
By origin and actor type
APT44
nation-state
Russia · 25 targets · since 2009
FIN10
cybercrime
unattributed · 1 targets · since 2013
FIN2
cybercrime
unattributed · 0 targets · since —
FIN6
cybercrime
Russia · 15 targets · since 2014
UNC1543
cybercrime
unattributed · 22 targets · since —
FIN3
cybercrime
unattributed · 1 targets · since —
T1053.005
Scheduled Task
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1204.001
Malicious Link
T1547.001
Registry Run Keys / Startup Folder
T1547.004
Winlogon Helper DLL
T1003.002
Security Account Manager
T1003.003
NTDS
T1552.006
Group Policy Preferences
T1555.004
Windows Credential Manager
T1557.001
Name Resolution Poisoning and SMB Relay
T1558.003
Kerberoasting
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1135
Network Share Discovery
T1021.001
Remote Desktop Protocol
T1021.002
SMB/Windows Admin Shares
T1021.006
Windows Remote Management
T1210
Exploitation of Remote Services
T1550.002
Pass the Hash
T1570
Lateral Tool Transfer
T1560.001
Archive via Utility
T1490
Inhibit System Recovery
T1105
Ingress Tool Transfer
T1685
Disable or Modify Tools
T1055
Process Injection
T1055.001
Dynamic-link Library Injection
T1070.004
File Deletion
T1078
Valid Accounts
T1078.002
Domain Accounts
T1197
BITS Jobs
T1218.011
Rundll32