National Cyber Warfare Foundation (NCWF)

FIN11


0 user ratings
2024-07-26 20:10:08
blscott

 - archive -- 
FIN11 is a well-established financial crime group that has recently focused its operations on ransomware and extortion. The group has been active since 2017 and has been tracked under UNC902 and later on as TEMP.Warlok. In some ways, FIN11 is reminiscent of APT1; they are notable not for their sophistication, but for their sheer volume of activity.(FireEye) Mandiant has also responded to numerous FIN11 intrusions, but weave only observed the group successfully monetize access in few instances. This could suggest that the actors cast a wide net during their phishing operations, then choose which victims to further exploit based on characteristics such as sector, geolocation or perceived security posture. Recently, FIN11 has deployed CLOP ransomware and threatened to publish exfiltrated data to pressure victims into paying ransom demands. The groupas shifting monetization methodsafrom point-of-sale (POS) malware in 2018, to ransomware in 2019, and hybrid extortion in 2020ais part of a larger trend in which criminal actors have increasingly focused on post-compromise ransomware deployment and data theft extortion. Notably, FIN11 includes a subset of the activity security researchers call TA505, Graceful Spider, Gold Evergreen, but we do not attribute TA505as early operations to FIN11 and caution against using the names interchangeably. Attribution of both historic TA505 activity and more recent FIN11 activity is complicated by the actorsa use of criminal service providers. Like most financially motivated actors, FIN11 doesnat operate in a vacuum. We believe that the group has used services that provide anonymous domain registration, bulletproof hosting, code signing certificates, and private or semi-private malware. Outsourcing work to these criminal service providers likely enables FIN11 to increase the scale and sophistication of their operations.

(FireEye) Mandiant has also responded to numerous FIN11
intrusions, but we’ve only observed the group successfully monetize access in
few instances. This could suggest that the actors cast a wide net during their
phishing operations, then choose which victims to further exploit based on
characteristics such as sector, geolocation or perceived security posture.
Recently, FIN11 has deployed CLOP ransomware and threatened to publish
exfiltrated data to pressure victims into paying ransom demands. The group’s shifting
monetization methods—from point-of-sale (POS) malware in 2018, to ransomware in
2019, and hybrid extortion in 2020—is part of a larger trend in which criminal
actors have increasingly focused on post-compromise ransomware deployment and
data theft extortion. Notably, FIN11 includes a subset of the activity security
researchers call \'TA505, Graceful Spider, Gold Evergreen\', but we do not
attribute TA505’s early operations to FIN11 and caution against using the names
interchangeably. Attribution of both historic TA505 activity and more recent
FIN11 activity is complicated by the actors’ use of criminal service providers.
Like most financially motivated actors, FIN11 doesn’t operate in a vacuum. We
believe that the group has used services that provide anonymous domain
registration, bulletproof hosting, code signing certificates, and private or
semi-private malware. Outsourcing work to these criminal service providers
likely enables FIN11 to increase the scale and sophistication of their
operations.



Other names

DEV-0950, FIN11, Lace Tempest, Operation “Cyclone”, TEMP.Warlock, UNC902,



First seen- 2016



 Target categories

mso-themecolor:text1\">Defense, mso-themecolor:text1\">Education, mso-themecolor:text1\">Energy, mso-themecolor:text1\">Financial, mso-themecolor:text1\">Hospitality, mso-themecolor:text1\">Retail, mso-themecolor:text1\">Technology, mso-themecolor:text1\">Telecommunications, mso-themecolor:text1\">Transportation,



Tools-



Amadey (category:
Malware)


type: Reconnaissance, Dropper

(Cylance) Amadey is a simple Trojan bot first discovered in October of 2018. It
is primarily used for collecting information on a victim\'s environment, though
it can also deliver other malware. A major infection vector for Amadey are
exploit kits such as RigEK and Fallout EK. During our monitoring, we also
observed this Trojan being delivered via AZORult Infostealer on February 23rd
to March 1st, and April 18th to June 5th. The sample hash values were not
changed frequently. Recently, TA505 used Amadey for their campaign in April
2019.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=26428c47-8df5-4c3c-864f-5c526f5bbdfc

https://threatvector.cylance.com/en_us/home/threat-spotlight-amadey-bot.html

https://krabsonsecurity.com/2019/02/13/analyzing-amadey-a-simple-native-malware/

https://securelist.com/fake-captcha-delivers-lumma-amadey/114312/

https://attack.mitre.org/software/S1025/

https://malpedia.caad.fkie.fraunhofer.de/details/win.amadey

https://otx.alienvault.com/browse/pulses?q=tag:amadey



AndroMut (category:
Malware)


type: Downloader

(Proofpoint) In June 2019, TA505 appears to have introduced yet another new
downloader malware, AndroMut, which has some similarities in code and behavior
to \'Andromeda\', a long-established malware family. Proofpoint research has
observed AndroMut download malware referred to as “\'FlawedAmmyy\'.”

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c0076597-3d86-4828-9c99-d8a9eefd9ee1

https://www.proofpoint.com/us/threat-insight/post/ta505-begins-summer-campaigns-new-pet-malware-downloader-andromut-uae-south

https://malpedia.caad.fkie.fraunhofer.de/details/win.andromut



AZORult (category:
Malware)


type: Info stealer, Credential stealer, Downloader

(Kaspersky) The AZORult Trojan is one of the most commonly bought and sold
stealers in Russian forums. Despite the relatively high price tag ($100),
buyers like AZORult for its broad functionality (for example, the use of .bit
domains as C&C servers to ensure owner anonymity and to make it difficult
to block the C&C server), as well as its high performance. Many comment
leavers recommend it. AZORult is a Trojan stealer that collects various data on
infected computers and sends it to the C&C server, including browser
history, login credentials, cookies, files from folders as specified by the
C&C server (for example, all TXT files from the Desktop folder),
cryptowallet files, etc.; the malware can also be used as a loader to download
other malware. Kaspersky Lab products detect the stealer as
Trojan-PSW.Win32.Azorult. Our statistics show that since the start of 2019,
users in Russia and India are the most targeted.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ce88f834-afbf-4d8b-8ca6-43b7fde7bdf2

https://securelist.com/azorult-analysis-history/89922/

https://threatvector.cylance.com/en_us/home/threat-spotlight-analyzing-azorult-infostealer-malware.html

https://blog.minerva-labs.com/puffstealer-evasion-in-a-cloak-of-multiple-layers

https://blog.minerva-labs.com/azorult-now-as-a-signed-google-update

https://www.proofpoint.com/us/threat-insight/post/new-version-azorult-stealer-improves-loading-features-spreads-alongside

https://www.blueliv.com/blog-news/research/azorult-crydbrox-stops-sells-malware-credential-stealer/

https://research.checkpoint.com/the-emergence-of-the-new-azorult-3-3/

https://www.netskope.com/blog/from-delivery-to-execution-an-evasive-azorult-campaign-smuggled-through-google-sites

https://attack.mitre.org/software/S0344/

https://malpedia.caad.fkie.fraunhofer.de/details/win.azorult



BLUESTEAL (category:
Malware)


type: POS malware, Credential stealer

In late 2018, Mandiant analysts observed FIN11 attempt to monetize their
operations using the point-of-sale (POS) memory scraping tool BLUESTEAL.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9b80b2af-9fcc-47d0-ab69-6bc0d8014f98



Clop (category:
Malware)


type: Ransomware, Big Game Hunting

Clop is a ransomware which uses the .clop extension after having encrypted the
victim\'s files. Another unique characteristic belonging with Clop is in the
string: \'Dont Worry C|0P\' included into the ransom notes. It is a variant of
\'CryptoMix\' ransomware, but it additionally attempts to disable Windows
Defender and to remove the Microsoft Security Essentials in order to avoid user
space detection.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=8792eefb-d852-4a24-ad09-46614ef7a815

https://www.mcafee.com/blogs/other-blogs/mcafee-labs/clop-ransomware/

https://www.bleepingcomputer.com/news/security/clop-ransomware-now-kills-windows-10-apps-and-3rd-party-tools/

https://www.telekom.com/en/blog/group/article/cybersecurity-ta505-returns-with-a-new-bag-of-tricks-602104

https://www.cybereason.com/blog/cybereason-vs.-clop-ransomware

https://www.notion.so/S2W-LAB-Analysis-of-Clop-Ransomware-suspiciously-related-to-the-Recent-Incident-English-088056baf01242409a6e9f844f0c5f2e

https://www.telekom.com/en/blog/group/article/inside-of-cl0p-s-ransomware-operation-615824

https://blog.malwarebytes.com/malwarebytes-news/2021/02/clop-targets-execs-ransomware-tactics-get-another-new-twist/

https://unit42.paloaltonetworks.com/clop-ransomware/

https://www.cybereason.com/blog/cl0p-ransomware-gang-tries-to-topple-the-house-of-cards

https://www.sentinelone.com/labs/cl0p-ransomware-targets-linux-systems-with-flawed-encryption-decryptor-available/

https://flashpoint.io/blog/clop-ransomware-threat/

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-158a

https://www.darkreading.com/dr-tech/cl0p-in-your-network-how-to-find-out

https://www.fortinet.com/blog/threat-research/ransomware-roundup-cl0p

https://attack.mitre.org/software/S0611/

https://malpedia.caad.fkie.fraunhofer.de/details/win.clop

https://otx.alienvault.com/browse/pulses?q=tag:Clop

https://pan-unit42.github.io/playbook_viewer/?pb=clop-ransomware



EMASTEAL (category:
Malware)


type: Info stealer

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=f557136d-7fa6-4d78-ae79-89e59c339c88



FlawedAmmyy (category:
Malware)


type: Backdoor, Info stealer, Credential stealer, Exfiltration

(Proofpoint) Ammyy Admin is a popular remote access tool used by businesses and
consumers to handle remote control and diagnostics on Microsoft Windows
machines. However, leaked source code for Version 3 of Ammyy Admin has emerged
as a Remote Access Trojan called FlawedAmmyy appearing in a variety of
malicious campaigns. For infected individuals, this means that attackers potentially
have complete access to their PCs, giving threat actors the ability to access a
variety of services, steal files and credentials, and much more. We have seen
FlawedAmmyy in both massive campaigns, potentially creating a large base of
compromised computers, as well as targeted campaigns that create opportunities
for actors to steal customer data, proprietary information, and more.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=12a4f267-6f13-4033-a9c9-f797fb2ebd45

https://www.proofpoint.com/us/threat-insight/post/leaked-ammyy-admin-source-code-turned-malware

https://www.sans.org/reading-room/whitepapers/reverseengineeringmalware/unpacking-decrypting-flawedammyy-38930

https://secrary.com/ReversingMalware/AMMY_RAT_Downloader/

https://www.proofpoint.com/us/threat-insight/post/ta505-abusing-settingcontent-ms-within-pdf-files-distribute-flawedammyy-rat

https://github.com/Coldzer0/Ammyy-v3

https://attack.mitre.org/software/S0381/

https://malpedia.caad.fkie.fraunhofer.de/details/win.flawedammyy

https://otx.alienvault.com/browse/pulses?q=tag:flawedammyy



FLOWERPIPE (category:
Malware)


No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=68122980-4411-4b36-8509-311bd532caae



FORKBEARD (category:
Malware)


type: Dropper

(FireEye) We observed FORKBEARD dropping \'SHORTBENCH\' and \'Meterpreter\' in an
April 2020 intrusion. FIN11 has used these Metasploit-related tools; however,
we currently have inadequate evidence to attribute this intrusion to FIN11.
SHORTBENCH and Meterpreter are used by a variety of actors.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d5a15a63-303e-4c09-9757-c6b91856508c



Get2 (category:
Malware)


type: Downloader

(Proofpoint) Get2 is a new downloader. Get2 was, in turn, observed downloading
\'FlawedGrace\', \'FlawedAmmyy\', \'Snatch\', and \'SDBbot\' (a new RAT) as secondary
payloads.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a4b9a235-29d6-4af1-a7ad-990854110c9f

https://www.proofpoint.com/us/threat-insight/post/ta505-distributes-new-sdbbot-remote-access-trojan-get2-downloader

https://attack.mitre.org/software/S0460/

https://malpedia.caad.fkie.fraunhofer.de/details/win.get2



JESTBOT (category:
Malware)


type: Backdoor

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=e913da6e-7d26-412a-8493-b89d9dea5918



Meterpreter (category:
Tools)


type: Loader

Meterpreter is an advanced, dynamically extensible payload that uses in-memory
DLL injection stagers and is extended over the network at runtime. It
communicates over the \'Metasploit Stager\' socket and provides a comprehensive
client-side Ruby API. It features command history, tab completion, channels,
and more. Meterpreter was originally written by skape for \'Metasploit\' 2.x,
common extensions were merged for 3.x and is currently undergoing an overhaul
for Metasploit 3.3. The server portion is implemented in plain C and is now
compiled with MSVC, making it somewhat portable. The client can be written in
any language but Metasploit has a full-featured Ruby client API.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=764acaf2-f0a0-4e7c-9933-d556cf0eb645

https://github.com/r00t-3xp10it/meterpeter

https://www.offensive-security.com/metasploit-unleashed/about-meterpreter/

https://malpedia.caad.fkie.fraunhofer.de/details/win.meterpreter

https://malpedia.caad.fkie.fraunhofer.de/details/apk.meterpreter

https://otx.alienvault.com/browse/pulses?q=tag:Meterpreter



MINEBRIDGE (category:
Malware)


type: Reconnaissance, Backdoor, Info stealer

(FireEye) MINEBRIDGE is a 32-bit C++ backdoor designed to be loaded by an
older, unpatched instance of the legitimate remote desktop software
\'TeamViewer\' by DLL load-order hijacking. The backdoor hooks Windows APIs to
prevent the victim from seeing the TeamViewer application. By default,
MINEBRIDGE conducts command and control (C2) communication via HTTPS POST
requests to hard-coded C2 domains. The POST requests contain a GUID derived
from the system’s volume serial number, a TeamViewer unique id and password,
username, computer name, operating system version, and beacon interval.
MINEBRIDGE can also communicate with a C2 server by sending TeamViewer chat
messages using a custom window procedure hook. Collectively, the two C2 methods
support commands for downloading and executing payloads, downloading arbitrary
files, self-deletion and updating, process listing, shutting down and rebooting
the system, executing arbitrary shell commands, process elevation, turning
on/off TeamViewer\'s microphone, and gathering system UAC information.
MINEBRIDGE’s default method of communication is sending HTTPS POST requests
over TCP port 443. This method of communication is always active; however, the
beacon-interval time may be changed via a command. Before sending any C2 beacons,
the sample waits to collect the TeamViewer generated unique id () and password
() via SetWindowsTextW hooks.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a84d3839-83ef-427c-b914-f46018515096

https://www.fireeye.com/blog/threat-research/2020/01/stomp-2-dis-brilliance-in-the-visual-basics.html

https://www.zscaler.com/blogs/security-research/return-minebridge-rat-new-ttps-and-social-engineering-lures

https://labs.sentinelone.com/breaking-ta505s-crypter-with-an-smt-solver/

https://blog.morphisec.com/minebridge-on-the-rise-sophisticated-delivery-mechanism

https://malpedia.caad.fkie.fraunhofer.de/details/win.minebridge

https://otx.alienvault.com/browse/pulses?q=tag:MINEBRIDGE



MINEDOOR (category:
Malware)


type: Dropper

(FireEye) In January 2020, Mandiant experts identified email campaigns that
used MINEDOOR to deliver the \'MINEBRIDGE\' backdoor. The limited overlap in TTPs
between these campaigns and contemporaneous FIN11 campaigns may suggest
MINEDOOR is not exclusive to FIN11.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ab9a9fd2-dc5d-4123-87e0-a8ccc21e928f



MIXLABEL (category:
Malware)


type: Backdoor, Downloader

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=9cf6cd6b-6b2d-46af-ba52-fca1fb03f0b7



NAILGUN (category:
Malware)


No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=af053bde-0f73-40e9-910f-458c1acd984f



POPFLASH (category:
Malware)


No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=fa00c1fd-2232-4ad8-b971-28106f8e543d



SALTLICK (category:
Malware)




No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=979b899a-221d-491a-8fae-ff4d5e95a993



SCRAPMINT (category:
Malware)


type: POS malware, Credential stealer



No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=a5b0bcbe-9db1-474a-ba6c-4f79a02f48f1



SHORTBENCH (category:
Tools)


type: Downloader, Loader

(FireEye) A downloader used to download and execute shellcode to download and
install additional malware and tools. It is a simple, lightweight and
open-sourced framework. SHORTBENCH can be used to download virtually any
follow-on payload and has been observed in use by diverse actors in a wide
range of event types.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=4f96b98f-027c-429e-86dc-5c73f7ed94ce

https://investors.fireeye.com/static-files/56c2c6ec-3cdc-4fd2-967e-29205d2e982e



SLOWROLL (category:
Malware)


type: Backdoor

No description available yet.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=d5ab26b6-6d1e-4287-a984-a2ae18daeebe



SPOONBEARD (category:
Malware)


type: Dropper

(FireEye) In May 2019, a SPOONBEARD-packed \'SCRAPMINT\' sample was uploaded to
VirusTotal. Based on several Mandiant incident response cases, we believe
SCRAPMINT has been used by multiple actors to conduct POS malware operations
including FIN6. Between August and December 2019, we identified SPOONBEARD
samples that delivered \'AZORult\' or \'VIDAR\' credential theft malware. It is
plausible that FIN11 used these credential stealers; however, both AZORult and
VIDAR have been sold on underground forums and are used by multiple actors. In
late 2019 and early 2020, we identified SPOONBEARD samples that delivered
\'SLOWROLL\' and \'JESTBOT\' respectively. SLOWROLL is a backdoor associated with
TEMP.TruthTeller (aka Silent Group) post-compromise activity.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=357bbbd7-42d1-45b6-af22-637727196ab6



TinyMet (category:
Tools)


type: Loader

A stager for \'Meterpreter\'.

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=439dc7a2-497d-4e50-847e-7c18ca9d6292

https://www.flashpoint-intel.com/blog/fin7-revisited:-inside-astra-panel-and-sqlrat-malware/

https://malpedia.caad.fkie.fraunhofer.de/details/win.tinymet



VIDAR (category:
Malware)


type: Info stealer, Credential stealer

Vidar is a forked malware based on Arkei. It seems this stealer is one of the
first that is grabbing information on 2FA Software and Tor Browser

https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ebc3d7df-80c6-4979-ae55-1bac4823e315

https://www.cybereason.com/blog/the-hole-in-the-bucket-attackers-abuse-bitbucket-to-deliver-an-arsenal-of-malware

https://medium.com/s2wlab/w1-feb-en-story-of-the-week-stealers-on-the-darkweb-49945a31601d

https://www.bleepingcomputer.com/news/security/gandcrab-operators-use-vidar-infostealer-as-a-forerunner/

https://tccontre.blogspot.com/2019/03/infor-stealer-vidar-trojanspy-analysis.html

https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf

https://fumik0.com/2018/12/24/lets-dig-into-vidar-an-arkei-copycat-forked-stealer-in-depth-analysis/

https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/vidar-malware-launcher-concealed-in-help-file/

https://asec.ahnlab.com/en/44554/

https://thehackernews.com/2023/01/raccoon-and-vidar-stealers-spreading.html

https://www.team-cymru.com/post/darth-vidar-the-aesir-strike-back

https://www.trendmicro.com/en_us/research/23/i/redline-vidar-first-abuses-ev-certificates.html

https://asec.ahnlab.com/en/58750/

https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar


Alternate Group Names
TEMP.Warlock, UNC902, 


Comments
new comment
Nobody has commented yet. Will you be the first?


Primary Names
TA505


a.k.a
White Austaras
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.