FinFisher

S0182

Malware.View on attack.mitre.org

About this malware

FinFisher is a government-grade commercial surveillance spyware reportedly sold exclusively to government agencies for use in targeted and lawful criminal investigations. It is heavily obfuscated and uses multiple anti-analysis techniques. It has other variants including Wingbird.

Techniques used22

Procedure examples22

TechniqueProcedure example
T1012
Query Registry

FinFisher queries Registry values as part of its anti-sandbox checks.

T1027
Obfuscated Files or Information

FinFisher is heavily obfuscated in many ways, including through the use of spaghetti code in its functions in an effort to confuse disassembly programs. It also uses a custom XOR algorithm to obfuscate code.

T1027.002
Software Packing

A FinFisher variant uses a custom packer.

T1027.016
Junk Code Insertion

FinFisher contains junk code in its functions in an effort to confuse disassembly programs.

T1036.005
Match Legitimate Resource Name or Location

FinFisher renames one of its .dll files to uxtheme.dll in an apparent attempt to masquerade as a legitimate file.

T1055.001
Dynamic-link Library Injection

FinFisher injects itself into various processes depending on whether it is low integrity or high integrity.

T1056.004
Credential API Hooking

FinFisher hooks processes by modifying IAT pointers to CreateWindowEx.

T1057
Process Discovery

FinFisher checks its parent process for indications that it is running in a sandbox setup.

T1082
System Information Discovery

FinFisher checks if the victim OS is 32 or 64-bit.

T1083
File and Directory Discovery

FinFisher enumerates directories and scans for certain files.

T1113
Screen Capture

FinFisher takes a screenshot of the screen and displays it on top of all other windows for few seconds in an apparent attempt to hide some messages showed by the system during the setup process.

T1134.001
Token Impersonation/Theft

FinFisher uses token manipulation with NtFilterToken as part of UAC bypass.

T1140
Deobfuscate/Decode Files or Information

FinFisher extracts and decrypts stage 3 malware, which is stored in encrypted resources.

T1497.001
System Checks

FinFisher obtains the hardware device list and checks if the MD5 of the vendor ID is equal to a predefined list in order to check for sandbox/virtualized environments.

T1518.001
Security Software Discovery

FinFisher probes the system to check for antimalware processes.

View all 22 procedure examples

Groups that use it1

Campaigns0

None recorded.

References5

  1. FinFisher Citation Open source
    FinFisher. (n.d.). Retrieved September 12, 2024.
  2. FireEye FinSpy Sept 2017 Open source
    Jiang, G., et al. (2017, September 12). FireEye Uncovers CVE-2017-8759: Zero-Day Used in the Wild to Distribute FINSPY. Retrieved February 15, 2018.
  3. Microsoft FinFisher March 2018 Open source
    Allievi, A.,Flori, E. (2018, March 01). FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines. Retrieved July 9, 2018.
  4. Microsoft SIR Vol 21 Open source
    Anthe, C. et al. (2016, December 14). Microsoft Security Intelligence Report Volume 21. Retrieved November 27, 2017.
  5. Securelist BlackOasis Oct 2017 Open source
    Kaspersky Lab's Global Research & Analysis Team. (2017, October 16). BlackOasis APT and new targeted attacks leveraging zero-day exploit. Retrieved February 15, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.