Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: TEMP.Warlock, UNC902, RAZOR COMET

Description

FIN11 is a well-established financial crime group that has recently focused its operations on ransomware and extortion. The group has been active since 2017 and has been tracked under UNC902 and later on as TEMP.Warlok. In some ways, FIN11 is reminiscent of APT1; they are notable not for their sophistication, but for their sheer volume of activity.(FireEye) Mandiant has also responded to numerous FIN11 intrusions, but we’ve only observed the group successfully monetize access in few instances. This could suggest that the actors cast a wide net during their phishing operations, then choose which victims to further exploit based on characteristics such as sector, geolocation or perceived security posture. Recently, FIN11 has deployed CLOP ransomware and threatened to publish exfiltrated data to pressure victims into paying ransom demands. The group’s shifting monetization methods—from point-of-sale (POS) malware in 2018, to ransomware in 2019, and hybrid extortion in 2020—is part of a larger trend in which criminal actors have increasingly focused on post-compromise ransomware deployment and data theft extortion. Notably, FIN11 includes a subset of the activity security researchers call TA505, Graceful Spider, Gold Evergreen, but we do not attribute TA505’s early operations to FIN11 and caution against using the names interchangeably. Attribution of both historic TA505 activity and more recent FIN11 activity is complicated by the actors’ use of criminal service providers. Like most financially motivated actors, FIN11 doesn’t operate in a vacuum. We believe that the group has used services that provide anonymous domain registration, bulletproof hosting, code signing certificates, and private or semi-private malware. Outsourcing work to these criminal service providers likely enables FIN11 to increase the scale and sophistication of their operations.

AI Analysis

· 2 weeks ago

Executive Summary

FIN11 is a financially motivated cybercriminal group active since 2017, known for shifting between POS malware, ransomware, and hybrid extortion tactics. The group leverages criminal service providers to scale operations, targeting organizations globally with spear-phishing campaigns and deploying CLOP ransomware. Recent activities emphasize data exfiltration and extortion, reflecting evolving monetization strategies.

Goals & Targeting

FIN11's primary objective is financial gain through ransomware extortion, data theft, and initial access sales. The group targets organizations across multiple sectors, with a focus on industries holding sensitive data or critical infrastructure. Victims are typically selected based on perceived vulnerability, sector profitability, and geolocation, with a particular emphasis on businesses in regions with weaker cybersecurity postures. The group's dynamic monetization strategies reflect a broader trend among financially motivated actors to exploit post-compromise opportunities for ransom extraction.

Enhanced Description

FIN11, also known as TEMP.Warlock and UNC902, is a financially driven threat actor with a history of adapting its tactics to maximize monetization. Initially associated with POS malware operations in 2018, the group transitioned to ransomware deployment in 2019 and adopted hybrid extortion models in 2020, involving both data encryption and exfiltration for leverage. The group's operations often begin with spear-phishing campaigns using malicious Office documents, followed by lateral movement and data theft. Notably, FIN11's use of third-party criminal services—such as anonymous domain registration and bulletproof hosting—allows it to maintain operational resilience and anonymity. While FireEye and Mandiant have observed numerous intrusions, successful monetization remains limited, suggesting a reliance on volume-based phishing to identify high-value targets. FIN11's activities overlap with TA505 (Graceful Spider) in certain periods but should not be conflated due to differing attribution timelines and operational structures.

Key Capabilities

  • Spear-phishing campaigns with malicious Office documents
  • Deployment of CLOP ransomware
  • Data exfiltration and extortion tactics
  • Use of bulletproof hosting and anonymous domain services
  • Integration with third-party criminal service providers
  • Lateral movement and credential harvesting via tools like Mimikatz

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Data Exfiltration
Impact

ATT&CK Techniques

T1059.003 - Manual Input
T1573.003 - DNS Tunneling
T1486 - Data Encrypted for Impact
T1038 - Data Extraction
T1055 - Credentials Access
T1192.002 - User Execution

Software / Tooling

CLOP Ransomware
Mimikatz
PowerShell
Custom Phishing Toolkits

Campaigns & Victims

FIN11's campaigns are characterized by a high operational tempo, with phishing campaigns serving as the primary entry vector. The group has demonstrated a pattern of evolving monetization methods, transitioning from POS malware to ransomware and hybrid extortion models. Campaigns often involve data exfiltration to pressure victims into paying ransoms, with a focus on sectors such as finance, healthcare, and critical infrastructure. Notable operations include the use of CLOP ransomware and the exploitation of third-party services to obfuscate infrastructure and maintain persistence.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication over DNS tunneling using fast-flux domains
  • Staging infrastructure on bulletproof hosting services
  • CLOP ransomware file encryption signatures
  • Exfiltration of sensitive data via compromised email servers

Recommended Actions

  • Implement advanced phishing simulations and employee training to reduce susceptibility to spear-phishing
  • Deploy network-based detection tools to identify DNS tunneling and C2 traffic anomalies
  • Conduct regular vulnerability assessments to mitigate lateral movement risks
  • Enforce multi-factor authentication (MFA) to protect against credential theft
  • Monitor for CLOP ransomware indicators and maintain offline backups of critical data

Suggested Tags

APT
ransomware
financial-crime
extortion
POS-malware

Confidence Assessment

Confidence in FIN11's activities is high, supported by reports from FireEye and Mandiant. However, gaps remain in fully understanding the group's internal structure, its full relationships with third-party criminal services, and the extent of its historical operations prior to 2017.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Critical Infrastructure
Phishing
Data Exfiltration
Hacktivism
APT
ransomware
financial-crime
extortion
POS-malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.