(FireEye) Mandiant has also responded to numerous FIN11
intrusions, but we’ve only observed the group successfully monetize access in
few instances. This could suggest that the actors cast a wide net during their
phishing operations, then choose which victims to further exploit based on
characteristics such as sector, geolocation or perceived security posture.
Recently, FIN11 has deployed CLOP ransomware and threatened to publish
exfiltrated data to pressure victims into paying ransom demands. The group’s shifting
monetization methods—from point-of-sale (POS) malware in 2018, to ransomware in
2019, and hybrid extortion in 2020—is part of a larger trend in which criminal
actors have increasingly focused on post-compromise ransomware deployment and
data theft extortion. Notably, FIN11 includes a subset of the activity security
researchers call \'TA505, Graceful Spider, Gold Evergreen\', but we do not
attribute TA505’s early operations to FIN11 and caution against using the names
interchangeably. Attribution of both historic TA505 activity and more recent
FIN11 activity is complicated by the actors’ use of criminal service providers.
Like most financially motivated actors, FIN11 doesn’t operate in a vacuum. We
believe that the group has used services that provide anonymous domain
registration, bulletproof hosting, code signing certificates, and private or
semi-private malware. Outsourcing work to these criminal service providers
likely enables FIN11 to increase the scale and sophistication of their
operations.
Other names
DEV-0950, FIN11, Lace Tempest, Operation “Cyclone”, TEMP.Warlock, UNC902,
First seen- 2016
Target categories
mso-themecolor:text1\">Defense, mso-themecolor:text1\">Education, mso-themecolor:text1\">Energy, mso-themecolor:text1\">Financial, mso-themecolor:text1\">Hospitality, mso-themecolor:text1\">Retail, mso-themecolor:text1\">Technology, mso-themecolor:text1\">Telecommunications, mso-themecolor:text1\">Transportation,
Tools-
Amadey (category:
Malware)
type: Reconnaissance, Dropper
(Cylance) Amadey is a simple Trojan bot first discovered in October of 2018. It
is primarily used for collecting information on a victim\'s environment, though
it can also deliver other malware. A major infection vector for Amadey are
exploit kits such as RigEK and Fallout EK. During our monitoring, we also
observed this Trojan being delivered via AZORult Infostealer on February 23rd
to March 1st, and April 18th to June 5th. The sample hash values were not
changed frequently. Recently, TA505 used Amadey for their campaign in April
2019.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=26428c47-8df5-4c3c-864f-5c526f5bbdfc
https://threatvector.cylance.com/en_us/home/threat-spotlight-amadey-bot.html
https://krabsonsecurity.com/2019/02/13/analyzing-amadey-a-simple-native-malware/
https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/
https://attack.mitre.org/software/S1025/
https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
https://otx.alienvault.com/browse/pulses?q=tag:amadey
AndroMut (category:
Malware)
type: Downloader
(Proofpoint) In June 2019, TA505 appears to have introduced yet another new
downloader malware, AndroMut, which has some similarities in code and behavior
to \'Andromeda\', a long-established malware family. Proofpoint research has
observed AndroMut download malware referred to as “\'FlawedAmmyy\'.”
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c0076597-3d86-4828-9c99-d8a9eefd9ee1
https://www.proofpoint.com/us/threat-insight/post/ta505-begins-summer-campaigns-new-pet-malware-downloader-andromut-uae-south
https://malpedia.caad.fkie.fraunhofer.de/details/win.andromut
AZORult (category:
Malware)
type: Info stealer, Credential stealer, Downloader
(Kaspersky) The AZORult Trojan is one of the most commonly bought and sold
stealers in Russian forums. Despite the relatively high price tag ($100),
buyers like AZORult for its broad functionality (for example, the use of .bit
domains as C&C servers to ensure owner anonymity and to make it difficult
to block the C&C server), as well as its high performance. Many comment
leavers recommend it. AZORult is a Trojan stealer that collects various data on
infected computers and sends it to the C&C server, including browser
history, login credentials, cookies, files from folders as specified by the
C&C server (for example, all TXT files from the Desktop folder),
cryptowallet files, etc.; the malware can also be used as a loader to download
other malware. Kaspersky Lab products detect the stealer as
Trojan-PSW.Win32.Azorult. Our statistics show that since the start of 2019,
users in Russia and India are the most targeted.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ce88f834-afbf-4d8b-8ca6-43b7fde7bdf2
https://securelist.com/azorult-analysis-history/89922/
https://threatvector.cylance.com/en_us/home/threat-spotlight-analyzing-azorult-infostealer-malware.html
https://blog.minerva-labs.com/puffstealer-evasion-in-a-cloak-of-multiple-layers
https://blog.minerva-labs.com/azorult-now-as-a-signed-google-update
https://www.proofpoint.com/us/threat-insight/post/new-version-azorult-stealer-improves-loading-features-spreads-alongside
https://www.blueliv.com/blog-news/research/azorult-crydbrox-stops-sells-malware-credential-stealer/
https://research.checkpoint.com/the-emergence-of-the-new-azorult-3-3/
https://www.netskope.com/blog/from-delivery-to-execution-an-evasive-azorult-campaign-smuggled-through-google-sites
https://attack.mitre.org/software/S0344/
https://malpedia.caad.fkie.fraunhofer.de/details/win.azorult
BLUESTEAL (category:
Malware)
type: POS malware, Credential stealer
In late 2018, Mandiant analysts observed FIN11 attempt to monetize their
operations using the point-of-sale (POS) memory scraping tool BLUESTEAL.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9b80b2af-9fcc-47d0-ab69-6bc0d8014f98
Clop (category:
Malware)
type: Ransomware, Big Game Hunting
Clop is a ransomware which uses the .clop extension after having encrypted the
victim\'s files. Another unique characteristic belonging with Clop is in the
string: \'Dont Worry C|0P\' included into the ransom notes. It is a variant of
\'CryptoMix\' ransomware, but it additionally attempts to disable Windows
Defender and to remove the Microsoft Security Essentials in order to avoid user
space detection.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8792eefb-d852-4a24-ad09-46614ef7a815
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/clop-ransomware/
https://www.bleepingcomputer.com/news/security/clop-ransomware-now-kills-windows-10-apps-and-3rd-party-tools/
https://www.telekom.com/en/blog/group/article/cybersecurity-ta505-returns-with-a-new-bag-of-tricks-602104
https://www.cybereason.com/blog/cybereason-vs.-clop-ransomware
https://www.notion.so/S2W-LAB-Analysis-of-Clop-Ransomware-suspiciously-related-to-the-Recent-Incident-English-088056baf01242409a6e9f844f0c5f2e
https://www.telekom.com/en/blog/group/article/inside-of-cl0p-s-ransomware-operation-615824
https://blog.malwarebytes.com/malwarebytes-news/2021/02/clop-targets-execs-ransomware-tactics-get-another-new-twist/
https://unit42.paloaltonetworks.com/clop-ransomware/
https://www.cybereason.com/blog/cl0p-ransomware-gang-tries-to-topple-the-house-of-cards
https://www.sentinelone.com/labs/cl0p-ransomware-targets-linux-systems-with-flawed-encryption-decryptor-available/
https://flashpoint.io/blog/clop-ransomware-threat/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a
https://www.darkreading.com/dr-tech/cl0p-in-your-network-how-to-find-out
https://www.fortinet.com/blog/threat-research/ransomware-roundup-cl0p
https://attack.mitre.org/software/S0611/
https://malpedia.caad.fkie.fraunhofer.de/details/win.clop
https://otx.alienvault.com/browse/pulses?q=tag:Clop
https://pan-unit42.github.io/playbook_viewer/?pb=clop-ransomware
EMASTEAL (category:
Malware)
type: Info stealer
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f557136d-7fa6-4d78-ae79-89e59c339c88
FlawedAmmyy (category:
Malware)
type: Backdoor, Info stealer, Credential stealer, Exfiltration
(Proofpoint) Ammyy Admin is a popular remote access tool used by businesses and
consumers to handle remote control and diagnostics on Microsoft Windows
machines. However, leaked source code for Version 3 of Ammyy Admin has emerged
as a Remote Access Trojan called FlawedAmmyy appearing in a variety of
malicious campaigns. For infected individuals, this means that attackers potentially
have complete access to their PCs, giving threat actors the ability to access a
variety of services, steal files and credentials, and much more. We have seen
FlawedAmmyy in both massive campaigns, potentially creating a large base of
compromised computers, as well as targeted campaigns that create opportunities
for actors to steal customer data, proprietary information, and more.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=12a4f267-6f13-4033-a9c9-f797fb2ebd45
https://www.proofpoint.com/us/threat-insight/post/leaked-ammyy-admin-source-code-turned-malware
https://www.sans.org/reading-room/whitepapers/reverseengineeringmalware/unpacking-decrypting-flawedammyy-38930
https://secrary.com/ReversingMalware/AMMY_RAT_Downloader/
https://www.proofpoint.com/us/threat-insight/post/ta505-abusing-settingcontent-ms-within-pdf-files-distribute-flawedammyy-rat
https://github.com/Coldzer0/Ammyy-v3
https://attack.mitre.org/software/S0381/
https://malpedia.caad.fkie.fraunhofer.de/details/win.flawedammyy
https://otx.alienvault.com/browse/pulses?q=tag:flawedammyy
FLOWERPIPE (category:
Malware)
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=68122980-4411-4b36-8509-311bd532caae
FORKBEARD (category:
Malware)
type: Dropper
(FireEye) We observed FORKBEARD dropping \'SHORTBENCH\' and \'Meterpreter\' in an
April 2020 intrusion. FIN11 has used these Metasploit-related tools; however,
we currently have inadequate evidence to attribute this intrusion to FIN11.
SHORTBENCH and Meterpreter are used by a variety of actors.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d5a15a63-303e-4c09-9757-c6b91856508c
Get2 (category:
Malware)
type: Downloader
(Proofpoint) Get2 is a new downloader. Get2 was, in turn, observed downloading
\'FlawedGrace\', \'FlawedAmmyy\', \'Snatch\', and \'SDBbot\' (a new RAT) as secondary
payloads.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a4b9a235-29d6-4af1-a7ad-990854110c9f
https://www.proofpoint.com/us/threat-insight/post/ta505-distributes-new-sdbbot-remote-access-trojan-get2-downloader
https://attack.mitre.org/software/S0460/
https://malpedia.caad.fkie.fraunhofer.de/details/win.get2
JESTBOT (category:
Malware)
type: Backdoor
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e913da6e-7d26-412a-8493-b89d9dea5918
Meterpreter (category:
Tools)
type: Loader
Meterpreter is an advanced, dynamically extensible payload that uses in-memory
DLL injection stagers and is extended over the network at runtime. It
communicates over the \'Metasploit Stager\' socket and provides a comprehensive
client-side Ruby API. It features command history, tab completion, channels,
and more. Meterpreter was originally written by skape for \'Metasploit\' 2.x,
common extensions were merged for 3.x and is currently undergoing an overhaul
for Metasploit 3.3. The server portion is implemented in plain C and is now
compiled with MSVC, making it somewhat portable. The client can be written in
any language but Metasploit has a full-featured Ruby client API.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=764acaf2-f0a0-4e7c-9933-d556cf0eb645
https://github.com/r00t-3xp10it/meterpeter
https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/
https://malpedia.caad.fkie.fraunhofer.de/details/win.meterpreter
https://malpedia.caad.fkie.fraunhofer.de/details/apk.meterpreter
https://otx.alienvault.com/browse/pulses?q=tag:Meterpreter
MINEBRIDGE (category:
Malware)
type: Reconnaissance, Backdoor, Info stealer
(FireEye) MINEBRIDGE is a 32-bit C++ backdoor designed to be loaded by an
older, unpatched instance of the legitimate remote desktop software
\'TeamViewer\' by DLL load-order hijacking. The backdoor hooks Windows APIs to
prevent the victim from seeing the TeamViewer application. By default,
MINEBRIDGE conducts command and control (C2) communication via HTTPS POST
requests to hard-coded C2 domains. The POST requests contain a GUID derived
from the system’s volume serial number, a TeamViewer unique id and password,
username, computer name, operating system version, and beacon interval.
MINEBRIDGE can also communicate with a C2 server by sending TeamViewer chat
messages using a custom window procedure hook. Collectively, the two C2 methods
support commands for downloading and executing payloads, downloading arbitrary
files, self-deletion and updating, process listing, shutting down and rebooting
the system, executing arbitrary shell commands, process elevation, turning
on/off TeamViewer\'s microphone, and gathering system UAC information.
MINEBRIDGE’s default method of communication is sending HTTPS POST requests
over TCP port 443. This method of communication is always active; however, the
beacon-interval time may be changed via a command. Before sending any C2 beacons,
the sample waits to collect the TeamViewer generated unique id () and password
() via SetWindowsTextW hooks.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a84d3839-83ef-427c-b914-f46018515096
https://www.fireeye.com/blog/threat-research/2020/01/stomp-2-dis-brilliance-in-the-visual-basics.html
https://www.zscaler.com/blogs/security-research/return-minebridge-rat-new-ttps-and-social-engineering-lures
https://labs.sentinelone.com/breaking-ta505s-crypter-with-an-smt-solver/
https://blog.morphisec.com/minebridge-on-the-rise-sophisticated-delivery-mechanism
https://malpedia.caad.fkie.fraunhofer.de/details/win.minebridge
https://otx.alienvault.com/browse/pulses?q=tag:MINEBRIDGE
MINEDOOR (category:
Malware)
type: Dropper
(FireEye) In January 2020, Mandiant experts identified email campaigns that
used MINEDOOR to deliver the \'MINEBRIDGE\' backdoor. The limited overlap in TTPs
between these campaigns and contemporaneous FIN11 campaigns may suggest
MINEDOOR is not exclusive to FIN11.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ab9a9fd2-dc5d-4123-87e0-a8ccc21e928f
MIXLABEL (category:
Malware)
type: Backdoor, Downloader
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9cf6cd6b-6b2d-46af-ba52-fca1fb03f0b7
NAILGUN (category:
Malware)
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=af053bde-0f73-40e9-910f-458c1acd984f
POPFLASH (category:
Malware)
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fa00c1fd-2232-4ad8-b971-28106f8e543d
SALTLICK (category:
Malware)
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=979b899a-221d-491a-8fae-ff4d5e95a993
SCRAPMINT (category:
Malware)
type: POS malware, Credential stealer
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a5b0bcbe-9db1-474a-ba6c-4f79a02f48f1
SHORTBENCH (category:
Tools)
type: Downloader, Loader
(FireEye) A downloader used to download and execute shellcode to download and
install additional malware and tools. It is a simple, lightweight and
open-sourced framework. SHORTBENCH can be used to download virtually any
follow-on payload and has been observed in use by diverse actors in a wide
range of event types.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4f96b98f-027c-429e-86dc-5c73f7ed94ce
https://investors.fireeye.com/static-files/56c2c6ec-3cdc-4fd2-967e-29205d2e982e
SLOWROLL (category:
Malware)
type: Backdoor
No description available yet.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d5ab26b6-6d1e-4287-a984-a2ae18daeebe
SPOONBEARD (category:
Malware)
type: Dropper
(FireEye) In May 2019, a SPOONBEARD-packed \'SCRAPMINT\' sample was uploaded to
VirusTotal. Based on several Mandiant incident response cases, we believe
SCRAPMINT has been used by multiple actors to conduct POS malware operations
including FIN6. Between August and December 2019, we identified SPOONBEARD
samples that delivered \'AZORult\' or \'VIDAR\' credential theft malware. It is
plausible that FIN11 used these credential stealers; however, both AZORult and
VIDAR have been sold on underground forums and are used by multiple actors. In
late 2019 and early 2020, we identified SPOONBEARD samples that delivered
\'SLOWROLL\' and \'JESTBOT\' respectively. SLOWROLL is a backdoor associated with
TEMP.TruthTeller (aka Silent Group) post-compromise activity.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=357bbbd7-42d1-45b6-af22-637727196ab6
TinyMet (category:
Tools)
type: Loader
A stager for \'Meterpreter\'.
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=439dc7a2-497d-4e50-847e-7c18ca9d6292
https://www.flashpoint-intel.com/blog/fin7-revisited:-inside-astra-panel-and-sqlrat-malware/
https://malpedia.caad.fkie.fraunhofer.de/details/win.tinymet
VIDAR (category:
Malware)
type: Info stealer, Credential stealer
Vidar is a forked malware based on Arkei. It seems this stealer is one of the
first that is grabbing information on 2FA Software and Tor Browser
https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ebc3d7df-80c6-4979-ae55-1bac4823e315
https://www.cybereason.com/blog/the-hole-in-the-bucket-attackers-abuse-bitbucket-to-deliver-an-arsenal-of-malware
https://medium.com/s2wlab/w1-feb-en-story-of-the-week-stealers-on-the-darkweb-49945a31601d
https://www.bleepingcomputer.com/news/security/gandcrab-operators-use-vidar-infostealer-as-a-forerunner/
https://tccontre.blogspot.com/2019/03/infor-stealer-vidar-trojanspy-analysis.html
https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf
https://fumik0.com/2018/12/24/lets-dig-into-vidar-an-arkei-copycat-forked-stealer-in-depth-analysis/
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/vidar-malware-launcher-concealed-in-help-file/
https://asec.ahnlab.com/en/44554/
https://thehackernews.com/2023/01/raccoon-and-vidar-stealers-spreading.html
https://www.team-cymru.com/post/darth-vidar-the-aesir-strike-back
https://www.trendmicro.com/en_us/research/23/i/redline-vidar-first-abuses-ev-certificates.html
https://asec.ahnlab.com/en/58750/
https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar
Alternate Group Names
TEMP.Warlock, UNC902,
