Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
17 malware familiesExploits CVEs in the wild

FIN11

Also known asFIN11

FIN11 is a long-running financially motivated cybercrime threat group associated in the provided content with ransomware deployment, data theft, and extortion. The group is repeatedly linked to the Cl0p/CLOP ransomware and extortion brand, and multiple sources in the content describe FIN11 as believed to be part of the broader TA505 umbrella. The content says FIN11 has been connected to both Russia and Ukraine, while other reporting links Cl0p to a Russian-language cybercriminal ecosystem. Microsoft maps FIN11 to Lace Tempest / DEV-0950. According to the content, FIN11 has monetized operations through point-of-sale malware, Clop ransomware, and traditional extortion, and has conducted long-running ransomware distribution campaigns across multiple industries. The group is associated with mass exploitation and extortion activity involving managed file transfer and enterprise application products. In the content, FIN11 or suspected FIN11 clusters are linked to exploitation and extortion activity involving Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo software, and Oracle E-Business Suite. Mandiant states that a suspected FIN11 cluster used the CL0P leak site and the Java-based GOLDVEIN.JAVA downloader in Oracle E-Business Suite exploitation activity in 2025. GTIG also reports strong links between a high-volume Oracle E-Business Suite extortion campaign and FIN11, including use of hundreds of compromised email accounts and at least one account directly tied to prior FIN11 activity. The content links FIN11 closely with Cl0p operations, including use of the CL0P data leak site, Cl0p ransomware deployment, and extortion campaigns that may prioritize data theft over encryption. Mandiant merged UNC4857 into FIN11 based on overlaps in targeting, infrastructure, certificates, and data leak site activity related to MOVEit exploitation. The content also notes that FIN11 appears to have multiple activity clusters, and several reports describe specific campaigns as attributable to an unknown or suspected FIN11 cluster rather than the entire actor set. Tradecraft described in the content includes ransomware distribution, mass exploitation of internet-facing applications, use of compromised accounts for extortion email campaigns, data exfiltration, and use of malware and web shells. For MOVEit exploitation, Mandiant attributed deployment of the LEMURLOOT web shell to activity later merged into FIN11. For Oracle E-Business Suite activity, the content links FIN11 to GOLDVEIN.JAVA and use of the CL0P leak site. FIN11 is also associated with process kill lists deployed alongside Clop ransomware; Mandiant attributed one Clop-associated kill list to FIN11 and noted that some listed processes were OT-related. The content further states that Mandiant emulated FIN11 in a red team engagement against a Europe-based engineering organization and demonstrated movement from a corporate endpoint with regular employee credentials to domain administrator privileges, theft of critical data, and access to OT servers. Mandiant says FIN11 has shown no indication of specialized OT expertise, but its use of kill lists containing OT-related processes raises concern about potential impact to OT environments. The content explicitly notes there is no evidence that FIN11’s OT-related kill list caused significant impacts in victim OT environments. Known aliases and related names directly mentioned in the content include Cl0p/CLOP, TA505, Lace Tempest, DEV-0950, and UNC4857 (merged into FIN11).

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics43 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1586
Compromise Accounts
TA0001
Initial Access
4 techniques
T1078×2
Valid Accounts
T1133
External Remote Services
T1190×16
Exploit Public-Facing Application
T1195×2
Supply Chain Compromise
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.004
Unix Shell
T1059.005
Visual Basic
T1203×2
Exploitation for Client Execution
TA0003
Persistence
5 techniques
T1078×2
Valid Accounts
T1098×2
Account Manipulation
T1133
External Remote Services
T1136
Create Account
T1505
Server Software Component
T1505.003×3
Web Shell
TA0004
Privilege Escalation
3 techniques
T1068×2
Exploitation for Privilege Escalation
T1078×2
Valid Accounts
T1098×2
Account Manipulation
TA0005
Stealth
2 techniques
T1036
Masquerading
T1078×2
Valid Accounts
TA0006
Credential Access
3 techniques
T1552
Unsecured Credentials
T1552.001
Credentials In Files
T1555
Credentials from Password Stores
T1649
Steal or Forge Authentication Certificates
TA0007
Discovery
2 techniques
T1057×2
Process Discovery
T1526
Cloud Service Discovery
TA0009
Collection
2 techniques
T1074×2
Data Staged
T1213×5
Data from Information Repositories
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001×2
Web Protocols
T1090
Proxy
T1090.003
Multi-hop Proxy
T1219
Remote Access Tools
TA0010
Exfiltration
3 techniques
T1041×5
Exfiltration Over C2 Channel
T1537
Transfer Data to Cloud Account
T1567×3
Exfiltration Over Web Service
T1567.002
Exfiltration to Cloud Storage
TA0040
Impact
5 techniques
T1486×8
Data Encrypted for Impact
T1489
Service Stop
T1490
Inhibit System Recovery
T1529
System Shutdown/Reboot
T1657×4
Financial Theft
WEAPONIZED

Associated vulnerabilities

13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.

CVE-2025-61882Unauthenticated RCE in Oracle E-Business Suite Concurrent Processing BI Publisher IntegrationIn the wildEvidence11

Cl0p (и связанный кластер FIN11) продолжила тактику массовой эксплуатации supply chain. По данным Cognyte, Cl0p провела кампанию с эксплуатацией критической zero-day CVE-2025-61882 ... в Oracle E-Business Suite (компонент BI Publisher Integration, версии 12.2.3-12.2.14). По данным NVD, CVSS 9.8 (Critical) ... эксплуатация не требует аутентификации и ведёт к полной компрометации. Уязвимость внесена в CISA KEV 2025-10-06. Около 30 организаций были опубликованы на DLS Cl0p с эксфильтрацией сотен гигабайт из Oracle EBS.

CVE-2023-34362SQL Injection in Progress MOVEit TransferIn the wildEvidence8

On May 31st, Progress Software issued an advisory and patch for a vulnerability subsequently identified as CVE-2023-34362 and assigned a severity rating of 9.8 out of 10. The company stated the vulnerability “could lead to escalated privileges and potential unauthorized access to the environment.” In other words, it was a vulnerability which could enable hackers to access MOVEit and steal data – something which it later emerged had been happening since at least May 27th.

CVE-2025-61884Authentication Bypass in Oracle E-Business Suite Oracle Configurator Runtime UIIn the wildEvidence3

“It’s still not clear which Oracle EBS zero-days have been exploited in the campaign claimed by Cl0p, but the main candidates are CVE-2025-61884 and CVE-2025-618842.”

CVE-2023-0669Pre-authentication RCE in Fortra GoAnywhere MFT License Response ServletIn the wildEvidence2

Similarly, in early 2023, threat actors exploited GoAnywhere Managed File Transfer (MFT) vulnerability CVE-2023-0669.

CVE-2021-35211RCE in SolarWinds Serv-U Managed File Transfer and Secure FTPIn the wildEvidence1

The Clop ransomware gang, also tracked as TA505 and FIN11, is exploiting a SolarWinds Serv-U vulnerability to breach corporate networks and ultimately encrypt its devices. The Serv-U Managed File Transfer and Serv-U Secure FTP remote code execution vulnerability, tracked as CVE-2021-35211, allows a remote threat actor to execute commands on a vulnerable server with elevated privileges.

8 more CVEs tied to this actor tracked in Mallory.

IOCS

Observables

11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping33

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal17

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs13

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables11

Domains, IPs, and hashes tied to this actor, refreshed continuously.