FinFly Web is a component of Gamma Group / Gamma International’s FinFisher (FinSpy) commercial surveillance suite. It is described in the provided content as a web-based exploitation server and a tool designed to provide remote and covert infection of target systems through a wide range of web-based attacks. Leaked brochure material states that operators could create custom infection code through a point-and-click interface. Support references mention FinFly Web licenses, downloadable updates, a static module, and an iFrame module, indicating multiple web-delivery mechanisms. The content also notes operational issues where antivirus products detected FinFly Web payloads or injected JavaScript, including ClamAV blocking injected JavaScript and reports that the static module triggered antivirus alerts. One support reference states iFrame-based delivery had issues on sites such as YouTube, Facebook, and Twitter. Source code for FinFly Web was reportedly leaked, and researchers described at least one leaked instance as a testing environment used to demonstrate capabilities to prospective clients. Kaspersky also reported suspected FinFly Web exploitation infrastructure in Europe, including two servers believed to host FinFly Web exploitation web applications; one was active from October 2019 to December 2020 and another appeared to impersonate Mail.ru around September 2020. The broader leaked FinFisher records associate FinFly Web with government and law-enforcement customers and licenses in countries including Slovakia and Mongolia. High-confidence aliases in the provided content only identify it as finfly_web / FinFly Web.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web-based exploitation server/tool suite used to profile victims and potentially deliver exploits/payloads; publicly documented in 2014.
Web-based infection/delivery component of the FinFisher/FinSpy ecosystem used to deliver FinSpy infections through web mechanisms such as static modules and iframe-based delivery.
Web-based infection component in the FinFisher suite used to deliver payloads through injected JavaScript/web infection workflows and generate payloads for targets including mobile devices.
Web-based infection component used to covertly infect target systems through prepared websites and custom infection code, delivering configured payloads such as FinSpy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.