FIN11 — Ransomware Profile

FIN11 is a financially motivated cybercrime group active since at least 2017, previously tracked as UNC902 and TEMP.Warlok. It is notable less for technical sophistication than for the sheer volume of its phishing operations, from which it selects a subset of victims for deeper exploitation based on sector, geography and apparent security posture. Its monetization has shifted repeatedly, from point-of-sale malware in 2018 to ransomware in 2019 and hybrid extortion from 2020, including CLOP ransomware deployments paired with threats to publish stolen data. Mandiant assesses that FIN11 overlaps with part of the activity other researchers track as TA505, Graceful Spider and Gold Evergreen, but cautions that the names are not interchangeable; the group's use of criminal service providers for bulletproof hosting, anonymous domain registration and code-signing certificates further complicates attribution.

Also tracked as

UNC2546, UNC2582, TEMP.Warlock, UNC902, RAZOR COMET

Tools & malware

Vendor research

Read the full analysis on IntelFusions