💰 Financial Crime theater
Covers financially motivated crime — banking trojans, BEC, wire fraud, carding, and ATM jackpotting — run by professional cybercrime syndicates. Protects financial institutions and payment rails by fusing malware C2, mule networks, and money-movement typologies.
Live indicators
0
in this theater
High severity
0
score ≥ 0.75 (top 60)
Actors tracked
7
documented
Mapped sources
18
in catalog
🏹 Threat Actors
📚 Priority sources & datasets
🔄 Live Datasets & APIs (10 key-free · ingestible)
📜 Financial Crime Playbook
- Ingest fraud reports, C2 feeds, and transaction telemetry from IC3, FinCEN filings, and abuse.ch on financially motivated activity.
- Enrich and deduplicate indicators, resolving mule accounts, cash-out infrastructure, and malware C2 into campaigns.
- Analyze money-movement typologies (BEC, wire fraud, ATM jackpotting, carding) and link them to intrusion sets.
- Attribute campaigns to financial threat groups (FIN7, Evil Corp, TA505, Cobalt) using TTP and infrastructure overlap.
- Brief financial institutions, FS-ISAC, and law enforcement with indicators and typology alerts.
- Push blocklists, freeze mule accounts, and file SAR and asset-seizure referrals.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Cross-domain pivots
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron