All actors

FIN6

Also reported as ITG08, Camouflage Tempest, Storm-0538, TAAL, White Giant and 22 other names. Linked to Russia by one source.

Reports
896
Last reported
Known CVEs
319
Techniques in ATT&CK
40
Origin
Russia
ID
G0037
Merge evidence
44 alias matches

Reports per quarter

  1. 2016 Q2: 2 reports
  2. 2016 Q3: no reports
  3. 2016 Q4: no reports
  4. 2017 Q1: no reports
  5. 2017 Q2: 2 reports
  6. 2017 Q3: 1 report
  7. 2017 Q4: 2 reports
  8. 2018 Q1: no reports
  9. 2018 Q2: 3 reports
  10. 2018 Q3: 5 reports
  11. 2018 Q4: 8 reports
  12. 2019 Q1: 15 reports
  13. 2019 Q2: 19 reports
  14. 2019 Q3: 4 reports
  15. 2019 Q4: 32 reports
  16. 2020 Q1: 39 reports
  17. 2020 Q2: 34 reports
  18. 2020 Q3: 40 reports
  19. 2020 Q4: 76 reports
  20. 2021 Q1: 53 reports
  21. 2021 Q2: 72 reports
  22. 2021 Q3: 67 reports
  23. 2021 Q4: 55 reports
  24. 2022 Q1: 59 reports
  25. 2022 Q2: 69 reports
  26. 2022 Q3: 44 reports
  27. 2022 Q4: 15 reports
  28. 2023 Q1: 19 reports
  29. 2023 Q2: 11 reports
  30. 2023 Q3: 14 reports
  31. 2023 Q4: 16 reports
  32. 2024 Q1: 9 reports
  33. 2024 Q2: 12 reports
  34. 2024 Q3: 19 reports
  35. 2024 Q4: 13 reports
  36. 2025 Q1: 8 reports
  37. 2025 Q2: 11 reports
  38. 2025 Q3: 7 reports
  39. 2025 Q4: 4 reports
  40. 2026 Q1: 5 reports
  41. 2026 Q2: 31 reports
  42. 2026 Q3: 1 report
Dated reports, 2016 Q2 to 2026 Q3.

Techniques seen in the last two years

Show all 272 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

CVEs named in reports

Show all 319 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

Show all 896 reports Show fewer
  1. FlawedAmmyy (Malware Family)

    date ORKL added it fromORKL

  2. Meterpreter (Malware Family)

    date ORKL added it fromORKL

  3. More_eggs (Malware Family)

    date ORKL added it fromORKL

  4. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  5. Ryuk (Malware Family)

    date ORKL added it fromORKL

  6. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  7. Unmasking Venom Spider

    date in the title fromORKL

  8. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  9. RedSense

    Malpedia library date fromORKL

  10. MORE_EGGS and Some LinkedIn Resumé Spearphishing

    date in the title fromORKL

  11. RedSense

    Malpedia library date fromORKL

  12. CERT-UA

    Malpedia library date fromORKL

  13. CERT-UA

    Malpedia library date fromORKL

  14. RedSense

    Malpedia library date fromORKL

  15. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  16. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  17. RedSense

    Malpedia library date fromORKL

  18. CERT-UA

    Malpedia library date fromORKL

  19. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  20. 2021trends.pdf

    Malpedia library date fromORKL

  21. RedSense

    Malpedia library date fromORKL

  22. Magecart Groups Abuse Google Tag Manager

    Malpedia library date fromORKL

  23. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  24. RedSense

    Malpedia library date fromORKL

  25. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  26. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  27. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  28. CTIR_casestudy_2.pdf

    file creation date fromORKL

  29. CTIR_casestudy_1.pdf

    file creation date fromORKL

  30. Intel 471

    Malpedia library date fromORKL

  31. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  32. mtrends-2021

    file creation date fromORKL

  33. Terraloader- Congrats, you have a new fake job!

    date in the title fromORKL

  34. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  35. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  36. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  37. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  38. Collaboration Between FIN7 and the RYUK Group

    date in the CCS '25 data Truesec fromORKLCCS '25 data

  39. SCYTHE Library: #ThreatThursday - Ryuk

    Malpedia library date fromORKL

  40. TinyPOS and ProLocker- An Odd Relationship

    date in the title fromORKL

  41. UNC1878 Indicators

    Malpedia library date fromORKL

  42. ESET_Threat_Report_Q32020

    file creation date fromORKL

  43. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  44. Tracing fresh Ryuk campaigns itw

    Malpedia library date fromORKL

  45. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  46. No Rest for the Wicked_ Evilnum Unleashes PyVil RAT

    date in the CCS '25 data Cybereason fromORKLCCS '25 data

  47. No Rest for the Wicked- Evilnum Unleashes PyVil RAT

    date in the title fromORKL

  48. wp-spark-state-of-ransomware.pdf

    file creation date fromORKL

  49. Golden Chickens- Evolution Oof the MaaS

    date in the title fromORKL

  50. More evil- A deep look at Evilnum and its toolset

    date in the title fromORKL

  51. More evil_ A deep look at Evilnum and its toolset _ WeLiveSecurity

    date in the CCS '25 data ESET fromORKLCCS '25 data

  52. Appendix C

    Malpedia library date fromORKL

  53. Talks - BrightTALK

    Malpedia library date fromORKL

  54. How to Deobfuscate Maze Ransomware | CrowdStrike

    Malpedia library date fromORKL

  55. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  56. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  57. They Come in the Night- Ransomware Deployment Trends

    date in the title fromORKL

  58. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  59. mtrends-2020

    file creation date fromORKL

  60. 2020_State-of-Malware-Report.pdf

    Malpedia library date fromORKL

  61. Dropping Anchor_ From a TrickBot Infection to the Discovery of the Anchor Malware

    date in the CCS '25 data Cybereason fromORKLCCS '25 data

  62. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  63. Shikata Ga Nai Encoder Still Going Strong

    date in the title fromORKL

  64. More_eggs, Anyone- Threat Actor ITG08 Strikes Again

    date in the title fromORKL

  65. More_eggs, Anyone_ Threat Actor ITG08 Strikes Again

    date in the CCS '25 data IBM fromORKLCCS '25 data

  66. Hunting and detecting Cobalt Strike

    date in the title fromORKL

  67. FlawedAmmyy

    date in the title fromORKL

  68. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  69. New Global Cyber Attack on Point of Sale Sytem

    date in the title fromORKL

  70. Software Description- More_eggs

    date in the title fromORKL

Newest first. Details opens the report in Explore.