FIN11 — Ransomware Profile
FIN11 is a financially motivated cybercrime group active since at least 2017, previously tracked as UNC902 and TEMP.Warlok. It is notable less for technical sophistication than for the sheer volume of its phishing operations, from which it selects a subset of victims for deeper exploitation based on sector, geography and apparent security posture. Its monetization has shifted repeatedly, from point-of-sale malware in 2018 to ransomware in 2019 and hybrid extortion from 2020, including CLOP ransomware deployments paired with threats to publish stolen data. Mandiant assesses that FIN11 overlaps with part of the activity other researchers track as TA505, Graceful Spider and Gold Evergreen, but cautions that the names are not interchangeable; the group's use of criminal service providers for bulletproof hosting, anonymous domain registration and code-signing certificates further complicates attribution.Also tracked as
UNC2546, UNC2582, TEMP.Warlock, UNC902, RAZOR COMET
Tools & malware
- CLOP ransomware ransomware
- DEWMODE web shell
- win.andromut Loader
- win.clop Ransomware
- win.dridex Banking Trojan
- win.flawedammyy Backdoor
- win.flawedgrace Remote Access Trojan
- win.get2 Backdoor
- win.locky Backdoor
- win.mirrorblast Backdoor
- win.rms Backdoor
- win.sdbbot Remote Access Trojan
- win.servhelper Backdoor
- win.silence Backdoor
- win.teleport Exfiltration Tool
- win.tinymet Backdoor
- win.trickbot Banking Trojan
Vendor research
- Cyber Criminals Exploit Accellion FTA for Data Theft and Extortion Mandiant (Google Cloud)
- FIN11: Widespread Email Campaigns as Precursor for Ransomware and Data Theft Mandiant (FireEye)