FinFisher, also widely known as FinSpy, is a commercial surveillance malware family associated with intrusive espionage operations against mobile and desktop systems. It has been documented on Windows, Linux, and macOS in bootkit-related contexts, and on Android and iOS in mobile surveillance use cases. The malware is designed for covert monitoring and data theft, with capabilities spanning collection, persistence, privilege escalation, defense evasion, and exfiltration.
On Windows, FinFisher has used DLL side-loading and DLL search order hijacking to execute malicious components through legitimate programs. It can inject itself into other processes, probe systems for antimalware processes, and inspect its parent process for signs of sandboxing or analysis environments. It has also used masquerading to make malicious components appear legitimate and has performed UAC bypass to gain elevated execution. Persistence has been established through Registry Run autostart mechanisms.
FinFisher also contains staged payload handling functionality, including extraction and decryption of later-stage malware from encrypted resources. In mobile surveillance scenarios, it has been observed capturing screenshots, recording phone conversations through the device microphone, accessing and exfiltrating call logs, and capturing and exfiltrating SMS messages. Exfiltration and command-and-control traffic have used commonly used network ports to blend with normal traffic.
The malware has been associated with exploitation chains involving Microsoft Office vulnerabilities including CVE-2017-0199 and CVE-2017-8759. FinFisher is best characterized as spyware focused on covert surveillance and data collection across both desktop and mobile platforms.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-8759 Vulnerable Products: Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 Associated Malware: FINSPY, FinFisher, WingBird Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-8759 ... Associated Malware: FINSPY, FinFisher, WingBird
CVE-2017-0199 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016, Vista SP2, Server 2008 SP2, Windows 7 SP1, Windows 8.1 Associated Malware: FINSPY, LATENTBOT, Dridex Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-0199 ... Associated Malware: FINSPY, LATENTBOT, Dridex
The developers of the commercial spyware FinSpy went one step further by adding a feature to intercept correspondence in secure messengers, such as Signal, Threema and others. To ensure interception, the app independently obtains root privileges by exploiting the vulnerability CVE-2016-5195, aka “Dirty Cow”.
FinSpy We may only intercept data when we have a warrant from the judge... So what we would like to do is putting the rootkit asleep at the last day of the warrant, and waken the rootkit again on the first day of the new warrant.
helper2 : Python exploit for CVE-2015-5889. This first stage uses the exploits to get root access. | FinSpy is a commercial spyware suite produced by the Munich-based company FinFisher Gmbh... FinSpy is a full-fledged surveillance software suite, capable of intercepting communications, accessing private data, and recording audio and video, from the computer or mobile devices it is silently installed on.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
We have previously reported on BlackOasis using other zero-days in the past; CVE-2016-4117 in May 2016, CVE-2016-0984 in June 2015, and CVE-2015-5119 in June 2015.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FinFisher is a spyware product manufactured by the Gamma Group, a British company that sells surveillance technology... Bill Marczak... and Morgan Marquis-Boire... analyzed the e-mails and found evidence that they contained FinSpy, part of the FinFisher spyware tool kit.
EFF has filed a lawsuit in federal court in Washington, DC alleging that the government of Ethiopia, using notorious surveillance malware known as FinSpy, illegally wiretapped and invaded the privacy of our client, a U.S. citizen on U.S. soil.
FinFisher is a sophisticated computer spyware suite, written by Munich-based FinFisher GmbH, and sold exclusively to governments for intelligence and law enforcement purposes.
FinFisher, one of the original suppliers of so-called "lawful intercept" spyware, has repeatedly been criticized for selling malware to countries with poor human rights records such as Bahrain, Egypt and Ethiopia.
FinSpy is a commercial spyware suite produced by the Munich-based company FinFisher Gmbh... FinSpy is a full-fledged surveillance software suite, capable of intercepting communications, accessing private data, and recording audio and video, from the computer or mobile devices it is silently installed on.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
The Phineas Fisher leaks unveiled what many suspected about these commercial spyware developers: they were knowingly selling surveillance tools to authoritarian regimes who used them to spy on civilians.
According to U.S. Government technical analysis, malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets.
U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600.
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Bootkits usually targeted MBR/ESP in the early 2010s, but as the cost of firmware attack decreased rapidly, the modern bootkits started to target DXE or even PEI.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process. | IAT HOOKING AND INLINE HOOKING (A.K.A USERLAND ROOTKITS) IAT hooking is a technique that malware uses to change the import address table.
To ensure interception, the app independently obtains root privileges by exploiting the vulnerability CVE-2016-5195, aka 'Dirty Cow'.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors that 'bypass UAC,' 'perform UAC bypass,' or use specific Windows components such as fodhelper.exe, eventvwr.exe, sdclt.exe, CMSTPLUA COM interface, SilentCleanup, and registry hijacks to gain elevated privileges.
In part one of this series, we analyzed the obfuscation on the x86 implementation of the FinSpy VM, and wrote a tool to deobfuscate it to allow easier analysis. | we begin Phase #1 by inspecting the FinSpy VM bytecode program, discovering obfuscation involving the "Group #2" instructions, and removing it via pattern-substitution.
Call aPLib unpacking routine to unpack bytecode. After unpacking, virtual opcodes are still encrypted.
Because the FinSpy VM is a weak and ineffective software protection, unpacking it is not very difficult. Over half of the VM instructions in the bytecode program for the sample we're analyzing already contain raw x86 machine code. It turns out that FinSpy only truly virtualizes a handful of x86 instruction types...
API functions are loaded dynamically, whereas in others they are referenced from the IAT of the binary, so these cases need to be handled accordingly.
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Process injection is a widespread defense evasion technique employed often within malware and fileless adversary tradecraft, and entails running custom code within the address space of another process. | IAT HOOKING AND INLINE HOOKING (A.K.A USERLAND ROOTKITS) IAT hooking is a technique that malware uses to change the import address table.
APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload.
The protected, virtualized sample must have the same behavior as a non-protected sample.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
Bootkits are a type of malware that infects the boot process of a computer, allowing attackers to gain persistent access and control over the system.
Bootkits usually targeted MBR/ESP in the early 2010s, but as the cost of firmware attack decreased rapidly, the modern bootkits started to target DXE or even PEI.
Man-in-the-Middle (MitM) attacks had been used to spread FinFisher, with the “man” in both cases most likely operating at the ISP level. On 8 October 2017, the same campaign resurfaced ... using the same (and very uncommon) structure of HTTP redirects to achieve “on-the-fly” browser redirection, only this time distributing Win32/StrongPity2 instead of FinFisher.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
The protected, virtualized sample must have the same behavior as a non-protected sample.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
The alleged hacking by officials in Bahrain “allowed access to and exfiltration of information on the computers...”
The content is a MITRE ATT&CK-style listing of malware and threat actors that "can capture screenshots," "take screenshots," "perform screen captures," or "watch the victim's screen." It ends with references to "CopyFromScreen" and "xwd."
...use of the computers’ microphones and cameras to surveil the respondents...
...use of the computers’ microphones and cameras to surveil the respondents...
Man-in-the-Middle (MitM) attacks had been used to spread FinFisher, with the “man” in both cases most likely operating at the ISP level. On 8 October 2017, the same campaign resurfaced ... using the same (and very uncommon) structure of HTTP redirects to achieve “on-the-fly” browser redirection, only this time distributing Win32/StrongPity2 instead of FinFisher.
FinFisher captures and exfiltrates SMS messages. FrozenCell has read SMS messages for exfiltration. Pallas captures and exfiltrates all SMS messages... Rotexy can also send a list of all SMS messages on the device to the command and control server. RuMMS uploads incoming SMS messages to a remote command and control server. Stealth Mango uploads SMS messages. Windshift has included SMS message exfiltration...
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
153 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Government spyware allegedly used to infect victims’ laptops, enabling access to and exfiltration of information, interception of communications, and use of microphones and cameras for surveillance. The content describes it as sophisticated spyware sold exclusively to governments for intelligence and law enforcement purposes.
Commercial spyware developed by Gamma Group; the article discusses it as one of the spyware products tied to Phineas Fisher's high-profile hacks and leaks.
Spyware previously detected in Jordan and cited as background on the Jordanian government’s apparent history of surveillance activity.
Commercial spyware referenced as an example of government procurement revealed through FOI requests.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.