APT
ATLAS
Atlas
Actors
147
Names
508
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
508
Sectors
40
Requirements
480
LOADING
FIN6 (aka ITG08, MageCart Group 6) · APT Atlas
Actors
/
Cybercrime
/
Europe
FIN6
G0037
CRIME
RU · Russia
AKA
ITG08 · MageCart Group 6 · TAAL
Microsoft
:
Camouflage Tempest
CrowdStrike
:
Skeleton Spider
MITRE
:
G0037
Secureworks
:
GOLD FRANKLIN
Targets
15
Sectors
2
Threat types
1
GIRs covered
0/480
Active since
2014
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 3 other aliases
Open Rosetta Stone
CrowdStrike
Skeleton Spider
Mandiant
FIN6
Microsoft
Camouflage Tempest
MITRE
G0037
Secureworks
GOLD FRANKLIN
UNATTRIBUTED ALIASES
ITG08
MageCart Group 6
TAAL
Victimology
Geographic footprint · 15 countries
Region filter
Export
origin · Russia
targeted countries · 15
AMERICAS ·
5
Canada
·
Chile
·
Colombia
·
United States
·
British Virgin Islands
EUROPE ·
5
Switzerland
·
Spain
·
France
·
United Kingdom
·
Ireland
ASIA ·
5
China
·
India
·
South Korea
·
Philippines
·
Singapore
Sectors targeted
2 of 40
Retail & Hospitality
33 actors
Hospitality
33 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
FIN · Financial Fraud
MITRE ATT&CK · 31 techniques
Initial Access
· 2
T1566.001
Spearphishing Attachment
T1566.003
Spearphishing via Service
Execution
· 6
T1047
Windows Management Instrumentation
Persistence
· 1
Privilege Escalation
· 1
T1068
Exploitation for Privilege Escalation
Credential Access
· 4
T1003.001
LSASS Memory
Discovery
· 2
T1018
Remote System Discovery
T1046
Network Service Discovery
Lateral Movement
· 1
T1021.001
Remote Desktop Protocol
Collection
· 4
T1005
Data from Local System
T1119
Automated Collection
T1560
Archive Collected Data
Exfiltration
· 1
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Command And Control
· 3
T1095
Non-Application Layer Protocol
T1102
Web Service
Defense Impairment
· 1
T1685
Disable or Modify Tools
Stealth
· 5
T1027.010
Command Obfuscation
T1036.004
Masquerade Task or Service
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
31 techniques · layer format 4.5
Related actors
By origin and actor type
Scattered Spider
cybercrime
United States · 3 targets · since 2022
APT44
nation-state
Russia · 25 targets · since 2009
FIN10
cybercrime
unattributed · 1 targets · since 2013
FIN2
cybercrime
unattributed · 0 targets · since —
UNC1543
cybercrime
unattributed · 22 targets · since —
FIN13
cybercrime
unattributed · 4 targets · since 2013
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.007
JavaScript
T1547.001
Registry Run Keys / Startup Folder
T1003.003
NTDS
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
T1560.003
Archive via Custom Method
T1573.002
Asymmetric Cryptography
T1070.004
File Deletion
T1078
Valid Accounts
T1134
Access Token Manipulation