CSIDB logo
Threat actor

FIN12

Attribution profile

Type
Criminal
Location
Russia
Known incidents
1 incident
First seen
2022-04-18
Last seen
2022-04-18
Updated
2026-08-28 17:17
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is referenced by the alias FIN12 in the available material.
This alias is the only identifier provided for the actor in the context.
The actor’s location is indicated as Russia.
No additional geographic details are supplied beyond this country‑level association.

The sources do not describe any particular sectors that the actor targets.
There is no mention of preferred industries, such as finance, health, or government.
Consequently, no regional focus beyond the stated location can be inferred.
The absence of targeting information means that strategic objectives remain unspecified.

No technical details about the actor’s methods are present in the provided texts.
No malware families, ransomware variants, or exploit kits are linked to FIN12.
Initial access vectors, such as phishing or vulnerability exploitation, are not discussed.
Tooling style, command‑and‑control infrastructure, or post‑exploitation behaviors are absent from the material.

Attribution to any state sponsor or criminal consortium is not established in the sources.
No affiliations with groups like Conti or other named collectives are cited for this alias.
Similarly, no specific campaigns, operations, or notable incidents are attributed to FIN12.
The only concrete facts available are the alias FIN12 and its Russian location, with all other characteristics unspecified in the given context.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB