Threat Theaters

💰 Financial Crime theater

Covers financially motivated crime — banking trojans, BEC, wire fraud, carding, and ATM jackpotting — run by professional cybercrime syndicates. Protects financial institutions and payment rails by fusing malware C2, mule networks, and money-movement typologies.

Live indicators

0
in this theater

High severity

0
score ≥ 0.75 (top 60)

Actors tracked

7
documented

Mapped sources

18
in catalog

🧭 Intelligence disciplines

FININT →CYBINT →OSINT →HUMINT →

📜 Financial Crime Playbook

  1. Ingest fraud reports, C2 feeds, and transaction telemetry from IC3, FinCEN filings, and abuse.ch on financially motivated activity.
  2. Enrich and deduplicate indicators, resolving mule accounts, cash-out infrastructure, and malware C2 into campaigns.
  3. Analyze money-movement typologies (BEC, wire fraud, ATM jackpotting, carding) and link them to intrusion sets.
  4. Attribute campaigns to financial threat groups (FIN7, Evil Corp, TA505, Cobalt) using TTP and infrastructure overlap.
  5. Brief financial institutions, FS-ISAC, and law enforcement with indicators and typology alerts.
  6. Push blocklists, freeze mule accounts, and file SAR and asset-seizure referrals.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php