Skip to content

FinFisher

FinFisher, also known as FinSpy, is commercial surveillance spyware developed and marketed by Gamma Group and FinFisher.

FinFisher

Family profile

FinFisher, also known as FinSpy, is commercial surveillance spyware developed and marketed by Gamma Group and FinFisher. It provides remote-access capabilities for digital espionage, allowing operators to access communications, files, internet activity, cameras, and microphones on compromised devices. Desktop variants target Windows, Linux, and macOS, while Android variants collect and exfiltrate call logs and SMS messages and use the microphone to record phone conversations. Its deployment has been associated with government surveillance of civil-society members and political dissidents.

FinFisher employs extensive anti-analysis measures, including sandbox-environment checks, parent-process inspection, anti-debugging routines, instruction obfuscation, control-flow flattening, and mixed Boolean-arithmetic expressions. Its multistage execution includes extracting and decrypting payloads embedded in encrypted resources. Windows variants use DLL side-loading and DLL search-order hijacking, bypass User Account Control, and establish persistence through Registry-based autostart mechanisms. Some variants incorporate boot-process persistence involving the master boot record or EFI system partition. FinFisher exfiltrates data over commonly used network ports to blend with ordinary traffic. Its deployment has also been associated with exploitation of CVE-2017-0199 and CVE-2017-8759.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Persistence
  • Privilege Escalation

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

7 named in public reporting
Kingdom of Bahrain

The claimants alleged that, starting in 2011, their devices in the United Kingdom were targeted with FinSpy spyware; the alleged conduct included installing and running the spyware, exfiltrating data, and activating microphones and cameras.

Gamma Group

FinFisher is a spyware product manufactured by the Gamma Group, a British company that sells surveillance technology... Bill Marczak... and Morgan Marquis-Boire... analyzed the e-mails and found evidence that they contained FinSpy, part of the FinFisher spyware tool kit.

Ethiopian government

EFF has filed a lawsuit in federal court in Washington, DC alleging that the government of Ethiopia, using notorious surveillance malware known as FinSpy, illegally wiretapped and invaded the privacy of our client, a U.S. citizen on U.S. soil.

Molerats

FinFisher is a sophisticated computer spyware suite, written by Munich-based FinFisher GmbH, and sold exclusively to governments for intelligence and law enforcement purposes.

Hacking Team

FinFisher, one of the original suppliers of so-called "lawful intercept" spyware, has repeatedly been criticized for selling malware to countries with poor human rights records such as Bahrain, Egypt and Ethiopia.

NilePhish

FinSpy is a commercial spyware suite produced by the Munich-based company FinFisher Gmbh... FinSpy is a full-fledged surveillance software suite, capable of intercepting communications, accessing private data, and recording audio and video, from the computer or mobile devices it is silently installed on.

BlackOasis

"...utilizes the popular ‘lawful surveillance’ kit FinSpy."

Exploited software

Vulnerabilities linked to FinFisher

8 CVEs

MITRE ATT&CK

FinFisher in ATT&CK

85 distinct techniques

Techniques

85 techniques
T1036.005 Match Legitimate Resource Name or Location T1027 Obfuscated Files or Information T1548.002 Bypass User Account Control T1082 System Information Discovery T1113 Screen Capture T1027.016 Junk Code Insertion T1057 Process Discovery T1543.003 Windows Service T1574.013 KernelCallbackTable T1574.001 DLL T1497.001 System Checks T1055.001 Dynamic-link Library Injection T1685.005 Clear Windows Event Logs T1547.001 Registry Run Keys / Startup Folder T1012 Query Registry T1083 File and Directory Discovery T1134.001 Token Impersonation/Theft T1056.004 Credential API Hooking T1518.001 Security Software Discovery T1027.002 Software Packing T1542.003 Bootkit T1140 Deobfuscate/Decode Files or Information T1056 Input Capture T1123 Audio Capture T1125 Video Capture T1105 Ingress Tool Transfer T1005 Data from Local System T1622 Debugger Evasion T1027.010 Command Obfuscation T1542 Pre-OS Boot T1055 Process Injection T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment T1036 Masquerading T1041 Exfiltration Over C2 Channel T1497 Virtualization/Sandbox Evasion T1574 Hijack Execution Flow T1027.007 Dynamic API Resolution T1553 Subvert Trust Controls T1195 Supply Chain Compromise T1027.006 HTML Smuggling T1557 Adversary-in-the-Middle T1068 Exploitation for Privilege Escalation T1542.001 System Firmware T1564.001 Hidden Files and Directories T1014 Rootkit T1189 Drive-by Compromise T1091 Replication Through Removable Media T1056.001 Keylogging T1071 Application Layer Protocol T1566.002 Spearphishing Link T1112 Modify Registry T1528 Steal Application Access Token T1649 Steal or Forge Authentication Certificates T1070 Indicator Removal T1587.001 Malware T1560 Archive Collected Data T1204.002 Malicious File T1566 Phishing T1564.003 Hidden Window T1555 Credentials from Password Stores T1040 Network Sniffing T1115 Clipboard Data T1090 Proxy T1059 Command and Scripting Interpreter T1090.003 Multi-hop Proxy T1048 Exfiltration Over Alternative Protocol T1204 User Execution T1132 Data Encoding T1070.004 File Deletion T1219 Remote Access Tools T1071.001 Web Protocols T1059.005 Visual Basic T1053 Scheduled Task/Job T1547 Boot or Logon Autostart Execution T1204.001 Malicious Link T1685 Disable or Modify Tools T1537 Transfer Data to Cloud Account T1684.001 Impersonation T1620 Reflective Code Loading T1659 Content Injection T1037 Boot or Logon Initialization Scripts T1543.001 Launch Agent T1573 Encrypted Channel T1574.004 Dylib Hijacking

Reporting

Research mentioning FinFisher

Aug 20
Splunk Research

Detection: Windows Phantom DLL Created on Disk | Splunk Security Content

NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.

Aug 19
Splunk Research

Detection: Windows Defender MpClient.dll Loaded by Non-Defender Process | Splunk Security Content

Aug 19
Splunk Research

Detection: Windows Alternate Data Stream Created Over Local Share | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Defender Threat Detected on Kernel Object Path | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Error Report Created in ReportQueue Manually | Splunk Security Content

Aug 18
Splunk Research

Detection: Windows Wermgr Spawning System Integrity Process | Splunk Security Content

Aug 17
Splunk Research

Shieldbreak | Splunk Security Content

Aug 13
Threatlocker

NightmareEclipse releases new PoC, ShieldBreak, exploits same weakness as RoguePlanet