FIN5
FIN5 is a financially motivated threat actor tracked as FIN5. In the provided content, FIN5 is associated with automated collection, command and scripting activity, use of proxying for access maintenance, use of legitimate administrative and dual-use tools, and anti-forensic cleanup. Specifically, FIN5 scanned processes across victim systems in an environment and used automated scripts to retrieve the results. The group maintained access in victim environments by using FLIPSIDE to create a proxy for a backup RDP tunnel. FIN5 scripts saved memory dump data into a specific directory on compromised hosts. FIN5 also used SDelete to clean up the environment and attempt to prevent detection. The content states FIN5 obtained and used a customized version of PsExec, and also used pwdump, SDelete, Windows Credential Editor, and the open-source tool Essential NetTools to map networks and build a list of targets. The content also associates FIN5 with ATT&CK techniques including T1059 Command and Scripting Interpreter, T1119 Automated Collection, T1129 Shared Modules, T1190 Exploit Public-Facing Application, T1505.003 Web Shell, and T1611 Escape to Host, but the supporting behavioral details directly described for FIN5 in the content are process scanning via scripts, memory-dump handling, proxy-backed RDP persistence, network mapping, and cleanup with SDelete. No additional aliases or sub-groups beyond FIN5 are provided in the content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Associated vulnerabilities
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
3 more CVEs tied to this actor tracked in Mallory.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed in the detection annotations as a threat actor associated with this analytic context.
Referenced in the detection annotations as a threat actor associated with reconnaissance/exploitation behavior relevant to Netspy-style network scanning.
Listed as an associated threat actor for this detection covering process access to the Windows Recall directory; no actor-specific activity, targeting, or campaign details are provided.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.