Reverse-engineering researchers published tooling and documentation that expose the inner workings of FinSpy, including a static unpacker, VM disassembler, and deobfuscation components hosted in the RolfRolles/FinSpyVM repository. The work targets FinSpy's custom virtual machine protection and provides practical artifacts for analysts to reconstruct protected code, while separate public documentation from the Chaos Computer Club details analysis of FinSpy for Android and includes leaked files, samples, graphs, tables, and a report on the spyware's components.
A technical walkthrough describing the devirtualization process said the analyzed FinSpy sample relied on a comparatively weak virtualization scheme in which much of the VM bytecode already contained raw x86 machine code. The author outlined a four-stage method for simplifying bytecode, recovering virtualized function calls and pointers, and performing a second devirtualization pass to produce a complete x86 code blob for loading into IDA, giving defenders and malware analysts a clearer path to inspect FinSpy behavior and internals.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A visible commit in the Chaos Computer Club's FinSpy documentation repository added a "phineas phisher torrent." The repository hosts documentation, leaked files, samples, graphs, tables, and a PDF report on FinSpy analysis.
A visible commit in the Chaos Computer Club's FinSpy documentation repository fixed parser output for "TlvTypeInstalledModules." This reflects ongoing maintenance of published analysis materials and tooling around FinSpy components.
The third and final part of a FinSpy VM unpacking series was published, detailing how the author reconstructed x86 code from FinSpy VM bytecode and produced a complete devirtualized code blob for analysis in IDA. The post describes the FinSpy VM protection as weak and explains the four-phase devirtualization process.
A GitHub repository titled "Static unpacker for FinSpy VM" was created to host tooling and notes for unpacking, VM analysis, disassembly, and devirtualization of FinSpy. The visible history shows an initial commit for FinSpyDeob.py and repository setup activity beginning on this date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcemsreverseengineering.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.