Also known as: TEMP.Warlock, UNC902, RAZOR COMET
FIN11 is a well-established financial crime group that has recently focused its operations on ransomware and extortion. The group has been active since 2017 and has been tracked under UNC902 and later on as TEMP.Warlok. In some ways, FIN11 is reminiscent of APT1; they are notable not for their sophistication, but for their sheer volume of activity.(FireEye) Mandiant has also responded to numerous FIN11 intrusions, but we’ve only observed the group successfully monetize access in few instances. This could suggest that the actors cast a wide net during their phishing operations, then choose which victims to further exploit based on characteristics such as sector, geolocation or perceived security posture. Recently, FIN11 has deployed CLOP ransomware and threatened to publish exfiltrated data to pressure victims into paying ransom demands. The group’s shifting monetization methods—from point-of-sale (POS) malware in 2018, to ransomware in 2019, and hybrid extortion in 2020—is part of a larger trend in which criminal actors have increasingly focused on post-compromise ransomware deployment and data theft extortion. Notably, FIN11 includes a subset of the activity security researchers call TA505, Graceful Spider, Gold Evergreen, but we do not attribute TA505’s early operations to FIN11 and caution against using the names interchangeably. Attribution of both historic TA505 activity and more recent FIN11 activity is complicated by the actors’ use of criminal service providers. Like most financially motivated actors, FIN11 doesn’t operate in a vacuum. We believe that the group has used services that provide anonymous domain registration, bulletproof hosting, code signing certificates, and private or semi-private malware. Outsourcing work to these criminal service providers likely enables FIN11 to increase the scale and sophistication of their operations.
Executive Summary
FIN11 is a financially motivated cybercriminal group active since 2017, known for shifting between POS malware, ransomware, and hybrid extortion tactics. The group leverages criminal service providers to scale operations, targeting organizations globally with spear-phishing campaigns and deploying CLOP ransomware. Recent activities emphasize data exfiltration and extortion, reflecting evolving monetization strategies.
Goals & Targeting
FIN11's primary objective is financial gain through ransomware extortion, data theft, and initial access sales. The group targets organizations across multiple sectors, with a focus on industries holding sensitive data or critical infrastructure. Victims are typically selected based on perceived vulnerability, sector profitability, and geolocation, with a particular emphasis on businesses in regions with weaker cybersecurity postures. The group's dynamic monetization strategies reflect a broader trend among financially motivated actors to exploit post-compromise opportunities for ransom extraction.
Enhanced Description
FIN11, also known as TEMP.Warlock and UNC902, is a financially driven threat actor with a history of adapting its tactics to maximize monetization. Initially associated with POS malware operations in 2018, the group transitioned to ransomware deployment in 2019 and adopted hybrid extortion models in 2020, involving both data encryption and exfiltration for leverage. The group's operations often begin with spear-phishing campaigns using malicious Office documents, followed by lateral movement and data theft. Notably, FIN11's use of third-party criminal services—such as anonymous domain registration and bulletproof hosting—allows it to maintain operational resilience and anonymity. While FireEye and Mandiant have observed numerous intrusions, successful monetization remains limited, suggesting a reliance on volume-based phishing to identify high-value targets. FIN11's activities overlap with TA505 (Graceful Spider) in certain periods but should not be conflated due to differing attribution timelines and operational structures.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
FIN11's campaigns are characterized by a high operational tempo, with phishing campaigns serving as the primary entry vector. The group has demonstrated a pattern of evolving monetization methods, transitioning from POS malware to ransomware and hybrid extortion models. Campaigns often involve data exfiltration to pressure victims into paying ransoms, with a focus on sectors such as finance, healthcare, and critical infrastructure. Notable operations include the use of CLOP ransomware and the exploitation of third-party services to obfuscate infrastructure and maintain persistence.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in FIN11's activities is high, supported by reports from FireEye and Mandiant. However, gaps remain in fully understanding the group's internal structure, its full relationships with third-party criminal services, and the extent of its historical operations prior to 2017.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics