FIN11 is a financially motivated cybercrime threat actor associated with long-running intrusion, ransomware deployment, and data-theft extortion activity. The group is widely linked to the broader TA505 ecosystem and has also been associated in reporting with Microsoft’s DEV-0950/Lace Tempest clustering and with Cl0p-related operations. Available reporting connects the actor primarily to Russian-language cybercriminal activity, with some references also linking elements of the operation to Ukraine. FIN11 has targeted organizations across multiple industries and geographies, including financial institutions, government-related entities, critical infrastructure, engineering, supply chain, health care, education, and energy-related organizations. Reported victim geographies include the United States, Canada, Japan, South Korea, India, Thailand, Singapore, Australia, Taiwan, New Zealand, the United Kingdom, and other parts of Europe and Southeast Asia. The actor is notable for combining opportunistic and targeted intrusion tradecraft with aggressive monetization. FIN11 has been linked to exploitation of public-facing applications and zero-day vulnerabilities, especially in managed file transfer and enterprise application products. Reported campaigns tie FIN11 or suspected FIN11 clusters to exploitation of Accellion FTA, Progress MOVEit Transfer, Cleo managed file transfer products, and Oracle E-Business Suite for large-scale theft of sensitive data followed by extortion. In several campaigns, the objective appears to have been exfiltration of customer, financial, and other sensitive business information for profit, including pure data-theft extortion without mandatory encryption. FIN11 has also been associated with Cl0p ransomware deployment and extortion operations. Reporting describes overlap or cooperation between FIN11 and Cl0p in campaigns involving stolen data publication on leak infrastructure, and some sources characterize FIN11 as part of, or closely overlapping with, TA505-affiliated ransomware activity. Historical reporting further links FIN11 to point-of-sale malware, traditional extortion, and ransomware distribution campaigns across multiple sectors. Observed capabilities attributed to FIN11 include initial access via phishing and exploitation of internet-facing systems, credential theft, privilege escalation, lateral movement, post-exploitation activity, persistence, defense evasion, and exfiltration. The group has been linked to use of malware loaders and commodity crimeware, deployment of web shells in server-side exploitation, abuse of administrative accounts, and ransomware-related process termination behavior intended to maximize operational impact. FIN11-linked activity has also been discussed in the context of operational technology risk because Cl0p-associated kill lists attributed to the group included some OT-related processes, although there is no confirmed evidence that FIN11 possesses specialized OT expertise or caused major OT disruption through those techniques. Overall, FIN11 is best characterized as a mature financially motivated intrusion actor focused on large-scale compromise and monetization through ransomware and extortion, with particular strength in exploiting high-value enterprise file-transfer and application infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
18 CVEs this actor has used in observed campaigns. 18 of them exploited in the wild.
Google Threat Intelligence Group documented that CVE-2025-61882 exploitation combined Server Side Request Forgery (SSRF), Carriage Return Line Feed (CRLF) injection, authentication bypass, and XSL template injection to achieve remote code execution... Known Exploitation Not confirmed Yes (Cl0p/FIN11, CISA KEV).
Clop ransomware specifically targets the MOVEIT Transfer vulnerability... The threat actors took advantage of a SQL injection vulnerability present in the web application of MOVEIT Transfer. They exploited this vulnerability by installing a webshell known as LEMURLOOT.
“It’s still not clear which Oracle EBS zero-days have been exploited in the campaign claimed by Cl0p, but the main candidates are CVE-2025-61884 and CVE-2025-618842.”
It's suspected that threat actors are exploiting CVE-2026-12569 (CVSS score: 9.3), a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month.
Similarly, in early 2023, threat actors exploited GoAnywhere Managed File Transfer (MFT) vulnerability CVE-2023-0669.
13 more CVEs tied to this actor tracked in Mallory.
81 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated in the content with Cl0p's supply-chain-oriented extortion operations.
Suspected operator linked by researchers to Oracle EBS intrusion activity; associated with tooling similarities between Oracle EBS attacks and prior mass exploitation campaigns.
Suspected FIN11 activity exploiting Oracle E-Business Suite, using the CL0P leak site and GOLDVEIN.JAVA in extortion-focused operations.
Referenced as a financially motivated threat actor associated with increased use of zero-day exploits in ransomware operations during 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.