The claimants alleged that, starting in 2011, their devices in the United Kingdom were targeted with FinSpy spyware; the alleged conduct included installing and running the spyware, exfiltrating data, and activating microphones and cameras.
FinFisher
FinFisher, also known as FinSpy, is commercial surveillance spyware developed and marketed by Gamma Group and FinFisher.
FinFisher
Family profile
FinFisher, also known as FinSpy, is commercial surveillance spyware developed and marketed by Gamma Group and FinFisher. It provides remote-access capabilities for digital espionage, allowing operators to access communications, files, internet activity, cameras, and microphones on compromised devices. Desktop variants target Windows, Linux, and macOS, while Android variants collect and exfiltrate call logs and SMS messages and use the microphone to record phone conversations. Its deployment has been associated with government surveillance of civil-society members and political dissidents.
FinFisher employs extensive anti-analysis measures, including sandbox-environment checks, parent-process inspection, anti-debugging routines, instruction obfuscation, control-flow flattening, and mixed Boolean-arithmetic expressions. Its multistage execution includes extracting and decrypting payloads embedded in encrypted resources. Windows variants use DLL side-loading and DLL search-order hijacking, bypass User Account Control, and establish persistence through Registry-based autostart mechanisms. Some variants incorporate boot-process persistence involving the master boot record or EFI system partition. FinFisher exfiltrates data over commonly used network ports to blend with ordinary traffic. Its deployment has also been associated with exploitation of CVE-2017-0199 and CVE-2017-8759.
Capabilities
- Defense Evasion
- Dll Sideloading
- Exfiltration
- Persistence
- Privilege Escalation
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
7 named in public reportingFinFisher is a spyware product manufactured by the Gamma Group, a British company that sells surveillance technology... Bill Marczak... and Morgan Marquis-Boire... analyzed the e-mails and found evidence that they contained FinSpy, part of the FinFisher spyware tool kit.
EFF has filed a lawsuit in federal court in Washington, DC alleging that the government of Ethiopia, using notorious surveillance malware known as FinSpy, illegally wiretapped and invaded the privacy of our client, a U.S. citizen on U.S. soil.
FinFisher is a sophisticated computer spyware suite, written by Munich-based FinFisher GmbH, and sold exclusively to governments for intelligence and law enforcement purposes.
FinFisher, one of the original suppliers of so-called "lawful intercept" spyware, has repeatedly been criticized for selling malware to countries with poor human rights records such as Bahrain, Egypt and Ethiopia.
FinSpy is a commercial spyware suite produced by the Munich-based company FinFisher Gmbh... FinSpy is a full-fledged surveillance software suite, capable of intercepting communications, accessing private data, and recording audio and video, from the computer or mobile devices it is silently installed on.
"...utilizes the popular ‘lawful surveillance’ kit FinSpy."
Exploited software
Vulnerabilities linked to FinFisher
8 CVEsMITRE ATT&CK
FinFisher in ATT&CK
85 distinct techniquesTechniques
85 techniquesReporting
Research mentioning FinFisher
Detection: Windows Phantom DLL Created on Disk | Splunk Security Content
NightmareEclipse released ShieldBreak, a proof-of-concept local privilege-escalation exploit claimed to bypass Microsoft’s fix for CVE-2026-50656 (RoguePlanet). The exploit allegedly abuses improper link resolution during Windows Defender remediation, combining Cloud Files placeholders, Object Manager symbolic-link swaps, CLFS path handling, an EICAR-triggered scan, and NTFS alternate data streams to redirect a Defender process running as SYSTEM and plant C:\Windows\System32\phoneinfo.dll. A fabricated Windows Error Reporting report and the QueueReporting scheduled task then cause wermgr.exe to load the malicious DLL; the included Warden.dll payload reportedly duplicates a SYSTEM token and opens a SYSTEM shell in the unprivileged user’s session. Splunk published attack data and multiple disabled-by-default analytics for the ShieldBreak chain, covering Defender activity on \globalroot\ object-manager paths (Defender Operational events 1116/1117), MpClient.dll loaded by non-Defender processes, ADS creation through loopback administrative SMB shares (Security event 5145), manually created .wer files in the Windows Error Reporting ReportQueue, creation of phantom DLLs such as phoneinfo.dll in system paths, and WerMgr.exe spawning SYSTEM-integrity children. Organizations should collect the required Sysmon, Security, and Defender Operational telemetry; enable file-share object-access auditing; investigate these signals promptly; and validate the creating process, signer, file hash, and operational need before suppressing alerts.