FIN10: Anatomy of a Cyber Extortion OperationFireEye has identified a set of financially motivated intrusion
operations being carried out by an actor we have dubbed FIN10.
Beginning as early as 2013 and continuing through at least 2016, we
have observed FIN10 primarily targeting casinos and mining
organizations in North America, with a focus on Canada.
We believe the primary goal of FIN10 is to steal corporate business
data, files, records, correspondence and customer PII for the purposes
of extorting victim organizations for the non-release of stolen data.
The group primarily demands as ransom in Bitcoins that equates to
anywhere from nearly $125,000 to more than $600,000.
Download our report,
FIN10: Anatomy
of a Cyber Extortion Operation, to learn more about FIN10, including:
- The publicly-available software, scripts, and techniques that
FIN10 primarily relies on to gain a foothold into victims’
networks. - How the threat group posts proof of the stolen data
on publicly accessible websites. - How failure to pay the
threat group could result in the public release of stolen data and
potential disruption or destruction of the victim’s information
assets and systems.
Additionally, FireEye provides many tips for dealing and interacting
with threat actors such as FIN10. Some of these recommendations include:
- Working quickly, staying focused, considering all options and
potentially involving forensic, legal, law enforcement and public
relations experts before taking any actions or communicating with
the threat actor. - Ensuring strong segmentation and controls
over backups so organizations can quickly recover from a
breach. - Focusing on broader security improvements once an
incident has been resolved, and ensuring the threat actor cannot
come back in a different way.
Although FireEye has observed FIN10 primarily targeting casinos and
mining organizations in North America (predominately in Canada), all
organizations from around the world must be prepared to detect and
respond to threats from this group and other bad actors.
Learn more
about FIN10 and how best to prevent, detect and respond to breaches.
Source:
FIN10: Anatomy of a Cyber Extortion Operation