FIN11 is a financially motivated cybercrime threat actor associated with long-running ransomware, data theft, and extortion operations. The group is widely linked to the broader TA505 ecosystem and is frequently associated with the Cl0p extortion and ransomware brand. Reporting also connects FIN11 activity to clusters tracked as UNC4857, later merged into FIN11, and UNC5936, a suspected FIN11-related cluster tied to Oracle E-Business Suite targeting. FIN11 has also been referenced in Microsoft’s taxonomy as Lace Tempest / DEV-0950. FIN11 has repeatedly targeted internet-facing enterprise file transfer and business application platforms, especially managed file transfer products and Oracle E-Business Suite, often using zero-day exploitation for initial access. High-confidence campaigns linked to FIN11 include exploitation of Accellion FTA, MOVEit Transfer, Cleo managed file transfer products, and Oracle E-Business Suite. In several of these operations, the objective was rapid large-scale data theft followed by extortion rather than immediate encryption, reflecting a shift toward data-theft extortion and leak-site pressure. FIN11-linked activity has been observed exploiting public-facing applications, deploying tailored web shells, and stealing data within minutes of successful compromise. The actor has a history of ransomware distribution and extortion across multiple industries. FIN11 has been linked to Cl0p ransomware deployment, use of leak-site infrastructure, and mass extortion campaigns using compromised email accounts. The group has monetized operations through ransomware, traditional extortion, and earlier criminal activity involving point-of-sale malware. FIN11 has also been associated with use of commodity and post-exploitation tooling including AZORult and Cobalt Strike, and with phishing-driven intrusion chains in addition to exploitation-based access. Observed tradecraft includes phishing, exploitation of public-facing applications, credential abuse, PowerShell and command-shell execution, web-shell persistence, data exfiltration, and extortion. FIN11-linked intrusions have also involved malware downloaders such as GOLDVEIN.JAVA, tailored web shells such as LEMURLOOT in MOVEit incidents, and process kill lists associated with Cl0p operations. Mandiant has assessed that FIN11 uses tactics comparable in some early intrusion phases to those seen in state-sponsored operations, including movement from enterprise environments toward operational technology networks, although there is no confirmed evidence that FIN11 possesses specialized OT expertise or has caused major OT-specific effects in the wild. FIN11 has targeted organizations across multiple sectors and geographies, with confirmed victim activity including North America, India, and Europe. High-confidence sector targeting includes financial services, health care, education, government-related entities, engineering and industrial organizations, and energy-related victims through Cl0p-linked mass exploitation campaigns. The group’s dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
18 CVEs this actor has used in observed campaigns. 18 of them exploited in the wild.
Google Threat Intelligence Group documented that CVE-2025-61882 exploitation combined Server Side Request Forgery (SSRF), Carriage Return Line Feed (CRLF) injection, authentication bypass, and XSL template injection to achieve remote code execution... Known Exploitation Not confirmed Yes (Cl0p/FIN11, CISA KEV).
Clop ransomware specifically targets the MOVEIT Transfer vulnerability... The threat actors took advantage of a SQL injection vulnerability present in the web application of MOVEIT Transfer. They exploited this vulnerability by installing a webshell known as LEMURLOOT.
“It’s still not clear which Oracle EBS zero-days have been exploited in the campaign claimed by Cl0p, but the main candidates are CVE-2025-61884 and CVE-2025-618842.”
It's suspected that threat actors are exploiting CVE-2026-12569 (CVSS score: 9.3), a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month.
Similarly, in early 2023, threat actors exploited GoAnywhere Managed File Transfer (MFT) vulnerability CVE-2023-0669.
13 more CVEs tied to this actor tracked in Mallory.
73 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated in the content with Cl0p's supply-chain-oriented extortion operations.
Suspected operator linked by researchers to Oracle EBS intrusion activity; associated with tooling similarities between Oracle EBS attacks and prior mass exploitation campaigns.
Suspected FIN11 activity exploiting Oracle E-Business Suite, using the CL0P leak site and GOLDVEIN.JAVA in extortion-focused operations.
Referenced as a financially motivated threat actor associated with increased use of zero-day exploits in ransomware operations during 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.