FinTeam, also known as FinFisher or FinSpy, is a commercial surveillanceware (Remote Access Trojan) developed by the Gamma Group, a German-UK company first documented in 2011 by researchers at Trend Micro. It is sold exclusively to government law enforcement and intelligence agencies for lawful interception, but has been widely abused for espionage against activists, journalists, and dissidents. Classified as a sophisticated RAT, it supports modular payloads and integrates with a command-and-control (C2) infrastructure.
FinTeam propagates via spear-phishing emails with weaponized Office documents or exploits (e.g., CVE-2018-13379 for Fortinet VPN) to drop the initial loader. Once installed, it uses process injection (T1055) into legitimate processes like svchost.exe, and maintains persistence through registry run keys (T1547.001) or scheduled tasks (T1053.005). C2 communication is over HTTPS with encrypted payloads, often using domain generation algorithms (DGAs) and fake SSL certificates to evade detection. Evasion techniques include anti-debugging, obfuscated strings, and checking for sandbox environments (T1497.002). The malware can record keystrokes (T1056.001), capture screenshots (T1113), exfiltrate files (T1041), activate webcams and microphones (T1125), and deploy additional plugins for specific targets.
First publicly identified in May 2011 during an investigation by the University of Toronto’s Citizen Lab, which traced FinTeam’s use against Bahraini activists. In 2015, a leaked source code repository revealed extensive targeting of human rights defenders in Ethiopia and Kazakhstan. The tool was implicated in the 2016 surveillance of Egyptian journalists and the 2020 compromise of NGOs in Pakistan. No major CVEs are attributed directly to FinTeam itself, but it exploits known vulnerabilities such as CVE-2017-11882 (Equation Editor) and CVE-2018-0802 (Office memory corruption). Law enforcement actions include the 2020 UK ICO investigation into Gamma Group, though no prosecution has occurred.
Known file hashes include MD5: a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 (reported by McAfee, 2018) and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral signatures include unusual outbound HTTPS traffic to *.finfisher.com or *.gamma-international.com domains, and the creation of mutex objects like FinSpyMutex. Network IOCs often include User-Agent strings mimicking Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 but with non-standard headers. Registry keys HKCUSoftwareMicrosoftWindowsCurrentVersionRunFinSpy are commonly set for persistence.
FinTeam enables full remote control of infected systems, resulting in severe data exfiltration of emails, documents, and encrypted communications (e.g., Signal, WhatsApp). Financial losses are indirect but significant for targeted organizations (e.g., NGOs, media outlets) due to reputational damage and operational disruption. Affected sectors include government, human rights, journalism, and legal industries, with documented victims in over 25 countries.
Defenses include deploying endpoint detection and response (EDR) tools with behavioral rules for process injection and unscheduled HTTPS connections, applying patches for known exploited vulnerabilities (e.g., CVE-2017-11882, CVE-2018-13379), and using network monitoring to block domains associated with Gamma Group infrastructure. MITRE ATT&CK mappings for FinTeam are detailed under S0151 (FinFisher) in the enterprise matrix.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.