FIN11
FIN11 is a long-running financially motivated cybercrime threat group associated in the provided content with ransomware deployment, data theft, and extortion. The group is repeatedly linked to the Cl0p/CLOP ransomware and extortion brand, and multiple sources in the content describe FIN11 as believed to be part of the broader TA505 umbrella. The content says FIN11 has been connected to both Russia and Ukraine, while other reporting links Cl0p to a Russian-language cybercriminal ecosystem. Microsoft maps FIN11 to Lace Tempest / DEV-0950. According to the content, FIN11 has monetized operations through point-of-sale malware, Clop ransomware, and traditional extortion, and has conducted long-running ransomware distribution campaigns across multiple industries. The group is associated with mass exploitation and extortion activity involving managed file transfer and enterprise application products. In the content, FIN11 or suspected FIN11 clusters are linked to exploitation and extortion activity involving Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo software, and Oracle E-Business Suite. Mandiant states that a suspected FIN11 cluster used the CL0P leak site and the Java-based GOLDVEIN.JAVA downloader in Oracle E-Business Suite exploitation activity in 2025. GTIG also reports strong links between a high-volume Oracle E-Business Suite extortion campaign and FIN11, including use of hundreds of compromised email accounts and at least one account directly tied to prior FIN11 activity. The content links FIN11 closely with Cl0p operations, including use of the CL0P data leak site, Cl0p ransomware deployment, and extortion campaigns that may prioritize data theft over encryption. Mandiant merged UNC4857 into FIN11 based on overlaps in targeting, infrastructure, certificates, and data leak site activity related to MOVEit exploitation. The content also notes that FIN11 appears to have multiple activity clusters, and several reports describe specific campaigns as attributable to an unknown or suspected FIN11 cluster rather than the entire actor set. Tradecraft described in the content includes ransomware distribution, mass exploitation of internet-facing applications, use of compromised accounts for extortion email campaigns, data exfiltration, and use of malware and web shells. For MOVEit exploitation, Mandiant attributed deployment of the LEMURLOOT web shell to activity later merged into FIN11. For Oracle E-Business Suite activity, the content links FIN11 to GOLDVEIN.JAVA and use of the CL0P leak site. FIN11 is also associated with process kill lists deployed alongside Clop ransomware; Mandiant attributed one Clop-associated kill list to FIN11 and noted that some listed processes were OT-related. The content further states that Mandiant emulated FIN11 in a red team engagement against a Europe-based engineering organization and demonstrated movement from a corporate endpoint with regular employee credentials to domain administrator privileges, theft of critical data, and access to OT servers. Mandiant says FIN11 has shown no indication of specialized OT expertise, but its use of kill lists containing OT-related processes raises concern about potential impact to OT environments. The content explicitly notes there is no evidence that FIN11’s OT-related kill list caused significant impacts in victim OT environments. Known aliases and related names directly mentioned in the content include Cl0p/CLOP, TA505, Lace Tempest, DEV-0950, and UNC4857 (merged into FIN11).
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
17 malware families attributed to this actor across reporting.
12 additional families tracked in Mallory.
Associated vulnerabilities
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
Cl0p (и связанный кластер FIN11) продолжила тактику массовой эксплуатации supply chain. По данным Cognyte, Cl0p провела кампанию с эксплуатацией критической zero-day CVE-2025-61882 ... в Oracle E-Business Suite (компонент BI Publisher Integration, версии 12.2.3-12.2.14). По данным NVD, CVSS 9.8 (Critical) ... эксплуатация не требует аутентификации и ведёт к полной компрометации. Уязвимость внесена в CISA KEV 2025-10-06. Около 30 организаций были опубликованы на DLS Cl0p с эксфильтрацией сотен гигабайт из Oracle EBS.
On May 31st, Progress Software issued an advisory and patch for a vulnerability subsequently identified as CVE-2023-34362 and assigned a severity rating of 9.8 out of 10. The company stated the vulnerability “could lead to escalated privileges and potential unauthorized access to the environment.” In other words, it was a vulnerability which could enable hackers to access MOVEit and steal data – something which it later emerged had been happening since at least May 27th.
“It’s still not clear which Oracle EBS zero-days have been exploited in the campaign claimed by Cl0p, but the main candidates are CVE-2025-61884 and CVE-2025-618842.”
Similarly, in early 2023, threat actors exploited GoAnywhere Managed File Transfer (MFT) vulnerability CVE-2023-0669.
The Clop ransomware gang, also tracked as TA505 and FIN11, is exploiting a SolarWinds Serv-U vulnerability to breach corporate networks and ultimately encrypt its devices. The Serv-U Managed File Transfer and Serv-U Secure FTP remote code execution vulnerability, tracked as CVE-2021-35211, allows a remote threat actor to execute commands on a vulnerable server with elevated privileges.
8 more CVEs tied to this actor tracked in Mallory.
Observables
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated in the content with Cl0p's supply-chain-oriented extortion operations.
Suspected FIN11 activity exploiting Oracle E-Business Suite, using the CL0P leak site and GOLDVEIN.JAVA in extortion-focused operations.
Referenced as a financially motivated threat actor associated with increased use of zero-day exploits in ransomware operations during 2025.
Referenced via Mandiant reporting related to email campaigns that act as a precursor for ransomware and data theft.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.