FinFisher, also known as FinSpy, is a commercial surveillance malware family developed and marketed by Gamma Group and FinFisher. It provides covert remote access for espionage, allowing operators to access communications, files, internet activity, cameras, and microphones. Mobile variants collect and exfiltrate call logs and SMS messages and can use the microphone to record phone conversations. The family includes malware targeting Windows, Linux, macOS, and Android and has been identified within Morocco’s digital-surveillance ecosystem.
FinFisher has been delivered through exploitation of Microsoft Office vulnerability CVE-2017-0199 and Microsoft .NET Framework vulnerability CVE-2017-8759. Windows variants use DLL side-loading and process injection, selecting injection targets according to their integrity level. They can bypass User Account Control and establish persistence through Registry-based autostart mechanisms. Bootkit-equipped variants also support persistence through manipulation of the boot process, including the master boot record and EFI System Partition.
FinFisher employs extensive defense-evasion and anti-analysis techniques. These include parent-process inspection, checks for characteristic sandbox system identifiers, anti-debugging routines, instruction obfuscation, mixed Boolean-arithmetic expressions, and control-flow flattening using Obfuscator-LLVM. During installation, it can overlay a captured screenshot to conceal system messages from the user.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attack begins with a phishing email containing an encrypted Excel file that exploits CVE-2017-0199. Upon opening the file, OLE objects are used to trigger the download and execution of a malicious HTA application.
The second, which ran from September 20 to 21, used an exploit for CVE-2017-8759 (patched last September), a code injection/remote code execution vulnerability in Microsoft’s .NET Framework. The vulnerability was used to retrieve and execute Cobalt Strike from a remote server they controlled. | The same exploit technique has been employed to deliver the cyberespionage malware FinSpy.
The developers of the commercial spyware FinSpy went one step further by adding a feature to intercept correspondence in secure messengers, such as Signal, Threema and others. To ensure interception, the app independently obtains root privileges by exploiting the vulnerability CVE-2016-5195, aka “Dirty Cow”.
FinSpy We may only intercept data when we have a warrant from the judge... So what we would like to do is putting the rootkit asleep at the last day of the warrant, and waken the rootkit again on the first day of the new warrant.
helper2 : Python exploit for CVE-2015-5889. This first stage uses the exploits to get root access. | FinSpy is a commercial spyware suite produced by the Munich-based company FinFisher Gmbh... FinSpy is a full-fledged surveillance software suite, capable of intercepting communications, accessing private data, and recording audio and video, from the computer or mobile devices it is silently installed on.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The claimants alleged that, starting in 2011, their devices in the United Kingdom were targeted with FinSpy spyware; the alleged conduct included installing and running the spyware, exfiltrating data, and activating microphones and cameras.
FinFisher is a spyware product manufactured by the Gamma Group, a British company that sells surveillance technology... Bill Marczak... and Morgan Marquis-Boire... analyzed the e-mails and found evidence that they contained FinSpy, part of the FinFisher spyware tool kit.
EFF has filed a lawsuit in federal court in Washington, DC alleging that the government of Ethiopia, using notorious surveillance malware known as FinSpy, illegally wiretapped and invaded the privacy of our client, a U.S. citizen on U.S. soil.
FinFisher is a sophisticated computer spyware suite, written by Munich-based FinFisher GmbH, and sold exclusively to governments for intelligence and law enforcement purposes.
FinFisher, one of the original suppliers of so-called "lawful intercept" spyware, has repeatedly been criticized for selling malware to countries with poor human rights records such as Bahrain, Egypt and Ethiopia.
FinSpy is a commercial spyware suite produced by the Munich-based company FinFisher Gmbh... FinSpy is a full-fledged surveillance software suite, capable of intercepting communications, accessing private data, and recording audio and video, from the computer or mobile devices it is silently installed on.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
What we can observe here is one of the most sophisticated code obfuscation techniques which is known as mixed Boolean-Arithmetic (MBA). MBAs arithmetically encode semantically simple operations in complex arithmetic expressions to hide the underlying computations.
The court listed “exfiltrating or causing information to be exfiltrated from the devices” among the causative acts; FinSpy also enabled access to files and communications stored on targets’ devices.
The government deployed ... Pegasus spyware to target civil society figures both domestically and abroad in what Amnesty described as “unlawful surveillance attacks.”
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
164 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Commercial surveillance spyware cited as part of Morocco's wider digital-espionage toolset.
Commercial spyware alleged to have been used by Bahrain to compromise the devices of two Bahraini dissidents living in the United Kingdom, forming the basis of litigation over state immunity and transnational repression.
Commercial spyware that gives its operator broad access to a compromised device, including communications, files, internet activity, camera, and microphone. It was allegedly used to surveil Bahraini dissidents in the United Kingdom.
Named in the historical background on malware delivered through similar CVE-2017-0199 campaigns. The report does not analyze its capabilities or connect it to the specific Remcos infection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.