Researchers published detailed reverse-engineering work on FinFisher/FinSpy spyware, showing how the surveillance tool hides its payload behind heavy anti-analysis protections and a proprietary virtual machine. ESET documented Windows samples that use complementary conditional-jump pairs after nearly every instruction to break disassembly, then decrypt and execute protected bytecode through a custom virtual CPU. The whitepaper describes how analysts can peel back those layers by reconstructing components such as vm_start, vm_dispatcher, vm_context, and vm_handlers, noting that the examined VM used 34 handlers and could mix virtualized logic with native instructions when full virtualization was impractical.
Additional reverse-engineering research expanded on that work by demonstrating how to simplify and devirtualize FinSpy bytecode into equivalent x86 logic. The analysis focused on removing instruction patterns tied to a dedicated SCRATCH register, replacing them with canonical VM forms or direct x86 operations, and decoding sequences that represented x86-style memory addressing and memory access. After those transformations, the remaining bytecode was reduced largely to branch and raw x86-related instructions, and the researcher also corrected an earlier interpretation of one opcode, concluding that a supposed CRASH instruction was actually an unconditional jump. Together, the findings show that FinFisher’s protections were built to frustrate reverse engineering and conceal configuration data and newer spyware capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2018-02-21, a Möbius Strip Reverse Engineering blog post detailed a phase of devirtualizing a FinSpy VM bytecode program by simplifying and eliminating Group #2 SCRATCH-register instructions. The post also corrected a prior reverse-engineering error by identifying a previously labeled "CRASH" instruction as an unconditional jump.
In January 2018, ESET published a whitepaper by Filip Kafka analyzing FinFisher's anti-disassembly protections and custom virtual machine used to conceal its payload. The paper documented deobfuscation and devirtualization techniques for the Windows spyware samples.
ESET reported that it discovered FinFisher surveillance campaigns in several countries during the summer of 2017. The company said some campaigns most probably involved internet service providers playing a key role in compromising victims.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.