FIN11 is a financially motivated cybercrime threat actor associated with large-scale extortion, ransomware deployment, and opportunistic mass exploitation of internet-facing enterprise software. The group is widely linked to the Cl0p extortion and ransomware ecosystem and is frequently described as overlapping with or operating within the broader TA505 criminal umbrella. Microsoft has also tracked related activity under the financially motivated Tempest naming scheme, including Lace Tempest / DEV-0950. Reporting indicates connections to Russian- and Ukrainian-linked cybercriminal milieus, but FIN11 is best characterized as a profit-driven criminal actor rather than a nation-state operator. FIN11 has targeted organizations across multiple industries worldwide, including finance, manufacturing, retail, transportation, education, healthcare, engineering, and other enterprise sectors. Its operations have included both traditional ransomware intrusion chains and exfiltration-led extortion campaigns in which encryption is optional or absent. The actor has been associated with point-of-sale malware activity, Cl0p ransomware deployment, and direct extortion using stolen data. A defining characteristic of FIN11 is repeated use of zero-day and n-day exploitation against managed file transfer and enterprise application platforms to enable broad victimization at scale. High-confidence public reporting links FIN11 or suspected FIN11 clusters to exploitation campaigns involving Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo managed file transfer products, and Oracle E-Business Suite. In several of these campaigns, the actor shifted from hands-on ransomware deployment toward rapid data theft followed by public leak-site pressure and executive-targeted extortion. FIN11 has been tied to the Cl0p leak site in multiple incidents, including MOVEit-related mass theft and later Oracle E-Business Suite extortion activity. The group’s tradecraft spans phishing, malware delivery, exploitation of public-facing applications, use of compromised accounts, and post-compromise extortion. FIN11 has historically been associated with malware families and tooling used in broader eCrime ecosystems, including AZORult and Cl0p-related tooling, and has been linked to Java-based downloader activity in Oracle E-Business Suite intrusions. Public reporting also notes use of large volumes of compromised email accounts to send extortion messages, a tactic consistent with high-scale pressure operations. FIN11 demonstrates operational flexibility in monetization. It has conducted ransomware distribution campaigns across many sectors, but more recent activity shows a strong emphasis on theft-first extortion, especially after exploiting file transfer and enterprise software vulnerabilities. This aligns with broader criminal trends in which data exfiltration and reputational pressure can replace encryption as the primary coercive mechanism. The actor has also drawn attention for tradecraft relevant to operational technology risk. Mandiant emulation of FIN11 techniques showed that a ransomware-oriented intrusion path could reach OT servers from standard enterprise access. FIN11-linked Cl0p activity has been associated with process kill lists that included some OT-related processes, indicating potential to disrupt industrial environments indirectly even without specialized OT expertise. Known aliases and related designations include Cl0p-associated FIN11 clusters, UNC5936 in suspected Oracle E-Business Suite activity, historical Mandiant cluster UNC4857 later merged into FIN11, and Microsoft’s Lace Tempest / DEV-0950. FIN11 is commonly discussed alongside Cl0p and TA505 due to overlapping infrastructure, tooling, victimology, and monetization patterns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
13 CVEs this actor has used in observed campaigns. 13 of them exploited in the wild.
Google Threat Intelligence Group documented that CVE-2025-61882 exploitation combined Server Side Request Forgery (SSRF), Carriage Return Line Feed (CRLF) injection, authentication bypass, and XSL template injection to achieve remote code execution... Known Exploitation Not confirmed Yes (Cl0p/FIN11, CISA KEV).
On May 31st, Progress Software issued an advisory and patch for a vulnerability subsequently identified as CVE-2023-34362 and assigned a severity rating of 9.8 out of 10. The company stated the vulnerability “could lead to escalated privileges and potential unauthorized access to the environment.” In other words, it was a vulnerability which could enable hackers to access MOVEit and steal data – something which it later emerged had been happening since at least May 27th.
“It’s still not clear which Oracle EBS zero-days have been exploited in the campaign claimed by Cl0p, but the main candidates are CVE-2025-61884 and CVE-2025-618842.”
Similarly, in early 2023, threat actors exploited GoAnywhere Managed File Transfer (MFT) vulnerability CVE-2023-0669.
The Clop ransomware gang, also tracked as TA505 and FIN11, is exploiting a SolarWinds Serv-U vulnerability to breach corporate networks and ultimately encrypt its devices. The Serv-U Managed File Transfer and Serv-U Secure FTP remote code execution vulnerability, tracked as CVE-2021-35211, allows a remote threat actor to execute commands on a vulnerable server with elevated privileges.
8 more CVEs tied to this actor tracked in Mallory.
42 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated in the content with Cl0p's supply-chain-oriented extortion operations.
Suspected operator linked by researchers to Oracle EBS intrusion activity; associated with tooling similarities between Oracle EBS attacks and prior mass exploitation campaigns.
Suspected FIN11 activity exploiting Oracle E-Business Suite, using the CL0P leak site and GOLDVEIN.JAVA in extortion-focused operations.
Referenced as a financially motivated threat actor associated with increased use of zero-day exploits in ransomware operations during 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.