Fin13 Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
April 22, 2026
Last Seen
July 23, 2026

Related Threat Clusters

  • MuddyWater Targets U.S. Entities Amid Geopolitical Tensions

    In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…

    16 articles · Updated July 22, 2026
  • FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector

    FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…

    10 articles · Updated May 13, 2026
  • Exploitation of Remote Services in Cyber Attacks

    Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…

    2 articles · Updated June 3, 2026
  • Cyber Adversaries Exploit File Enumeration and Data Collection Techniques

    Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…

    2 articles · Updated April 22, 2026

Recent Intelligence Reports

  • 001 — attack.mitre.org · July 23, 2026
  • External Remote Services — attack.mitre.org · June 3, 2026
  • T1505.003 Web Shell — attack.mitre.org · May 13, 2026
  • T1005 — attack.mitre.org · April 22, 2026
  • T1083 — attack.mitre.org · April 22, 2026

CVSS v3.1 Breakdown