APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
FIN8 (aka Syssphinx) · APT Atlas
Actors
/
Cybercrime
/
Unattributed
FIN8
G0061
CRIME
?? · Unattributed
AKA
Syssphinx
CrowdStrike
:
GRACEFUL SPIDER
MITRE
:
G0061
Secureworks
:
GOLD SNOWFLAKE
Targets
8
Sectors
0
Threat types
2
GIRs covered
0/480
Active since
2016
Pin to atlas
Watch
Share
Export
Also tracked as
4 vendor names · 1 other aliases
Open Rosetta Stone
CrowdStrike
GRACEFUL SPIDER
Mandiant
FIN8
MITRE
G0061
Secureworks
GOLD SNOWFLAKE
UNATTRIBUTED ALIASES
Syssphinx
Victimology
Geographic footprint · 8 countries
Region filter
Export
origin · unattributed
targeted countries · 8
AMERICAS ·
2
Canada
·
United States
EUROPE ·
3
France
·
United Kingdom
·
Italy
ASIA ·
3
Hong Kong
·
Japan
·
Singapore
Sectors targeted
0 of 40
No sectors targeted yet for this actor.
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
FIN · Financial Fraud
RAN · Ransomware
MITRE ATT&CK · 26 techniques
Initial Access
· 2
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
Execution
· 5
T1047
Windows Management Instrumentation
Privilege Escalation
· 1
T1068
Exploitation for Privilege Escalation
Credential Access
· 1
T1003.001
LSASS Memory
Discovery
· 3
T1018
Remote System Discovery
Lateral Movement
· 2
T1021.001
Remote Desktop Protocol
T1021.002
Collection
· 1
T1560.001
Archive via Utility
Exfiltration
· 1
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Impact
· 1
T1486
Data Encrypted for Impact
Command And Control
· 4
T1071.001
Web Protocols
T1102
Web Service
Defense Impairment
· 1
T1112
Modify Registry
Stealth
· 4
T1027.010
Command Obfuscation
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
26 techniques · layer format 4.5
Related actors
By origin and actor type
FIN10
cybercrime
unattributed · 1 targets · since 2013
FIN2
cybercrime
unattributed · 0 targets · since —
FIN6
cybercrime
Russia · 15 targets · since 2014
APT73
nation-state
unattributed · 0 targets · since —
UNC1543
cybercrime
unattributed · 22 targets · since —
FIN3
cybercrime
unattributed · 1 targets · since —
T1053.005
Scheduled Task
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1204.001
Malicious Link
T1033
System Owner/User Discovery
T1482
Domain Trust Discovery
SMB/Windows Admin Shares
T1105
Ingress Tool Transfer
T1573.002
Asymmetric Cryptography
T1055.004
Asynchronous Procedure Call
T1070.004
File Deletion
T1078
Valid Accounts