FIN11 is a financially motivated cybercrime threat actor associated with large-scale data theft, extortion, and ransomware operations. The group is widely linked to the CL0P extortion and ransomware ecosystem and is often described as part of, or closely associated with, the broader TA505 umbrella. Reporting has also connected FIN11 to activity clusters tracked under names including UNC5936, and historical attribution around CL0P-related mass exploitation has included overlaps with clusters later merged into FIN11. The actor has been associated with Russian-speaking cybercrime and has been linked in reporting to operators connected to Russia and Ukraine, but it is not a nation-state actor. FIN11 is notable for combining opportunistic mass exploitation with enterprise-scale extortion. The group has repeatedly targeted internet-facing managed file transfer and enterprise application platforms, including MOVEit Transfer, Accellion FTA, Cleo managed file transfer products, and Oracle E-Business Suite. Multiple campaigns attributed to FIN11 or suspected FIN11 clusters involved zero-day exploitation followed by rapid data theft and extortion, often without relying primarily on file encryption. This pattern aligns with the broader shift in the CL0P ecosystem toward exfiltration-led extortion and public leak-site pressure. The actor has been tied to exploitation campaigns involving CVE-2023-34362 in MOVEit Transfer, CVE-2024-55956 in Cleo managed file transfer products, and Oracle E-Business Suite zero-day activity in 2025 involving CVE-2025-61882 and/or CVE-2025-61884. FIN11-linked operations have also been associated with extortion campaigns in which attackers used large numbers of compromised email accounts to pressure executives while claiming affiliation with CL0P. In Oracle E-Business Suite intrusions, reporting linked the activity to use of the CL0P leak site and the GOLDVEIN.JAVA downloader. FIN11 has historically monetized through several models, including point-of-sale malware, ransomware deployment, and pure extortion. The group has been associated with malware families and tooling used across financially motivated intrusion chains, including CL0P ransomware and AZORult, and has demonstrated use of web shells, downloaders, living-off-the-land techniques, and post-compromise tooling consistent with mature eCrime operations. In ransomware contexts, FIN11 activity has included process-kill logic intended to maximize operational impact prior to encryption or extortion. The group’s tradecraft emphasizes speed and scale after initial access. Observed behavior includes exploitation of public-facing applications, deployment of tailored web shells for file enumeration and theft, credential abuse, use of compromised accounts for follow-on extortion, and mass victim notification through leak-site branding. FIN11 has also been emulated in red-team exercises to demonstrate how a financially motivated actor can pivot from standard enterprise access to domain-wide compromise, critical data theft, and even access to operational technology environments. Although there is no confirmed evidence that FIN11 possesses specialized OT expertise, its tooling and process-kill behavior have raised concern that its operations could disrupt OT-dependent organizations. Known aliases and closely associated names include CL0P, Clop, TA505, Lace Tempest, DEV-0950, and UNC5936, though some of these labels may refer to overlapping clusters, branding, or broader ecosystems rather than exact one-to-one equivalence. FIN11 is best understood as a mature, profit-driven intrusion actor that has repeatedly used high-tempo exploitation and extortion campaigns against organizations across multiple sectors worldwide.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
14 CVEs this actor has used in observed campaigns. 14 of them exploited in the wild.
Google Threat Intelligence Group documented that CVE-2025-61882 exploitation combined Server Side Request Forgery (SSRF), Carriage Return Line Feed (CRLF) injection, authentication bypass, and XSL template injection to achieve remote code execution... Known Exploitation Not confirmed Yes (Cl0p/FIN11, CISA KEV).
On May 31st, Progress Software issued an advisory and patch for a vulnerability subsequently identified as CVE-2023-34362 and assigned a severity rating of 9.8 out of 10. The company stated the vulnerability “could lead to escalated privileges and potential unauthorized access to the environment.” In other words, it was a vulnerability which could enable hackers to access MOVEit and steal data – something which it later emerged had been happening since at least May 27th.
“It’s still not clear which Oracle EBS zero-days have been exploited in the campaign claimed by Cl0p, but the main candidates are CVE-2025-61884 and CVE-2025-618842.”
It's suspected that threat actors are exploiting CVE-2026-12569 (CVSS score: 9.3), a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month.
Similarly, in early 2023, threat actors exploited GoAnywhere Managed File Transfer (MFT) vulnerability CVE-2023-0669.
9 more CVEs tied to this actor tracked in Mallory.
48 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster associated in the content with Cl0p's supply-chain-oriented extortion operations.
Suspected operator linked by researchers to Oracle EBS intrusion activity; associated with tooling similarities between Oracle EBS attacks and prior mass exploitation campaigns.
Suspected FIN11 activity exploiting Oracle E-Business Suite, using the CL0P leak site and GOLDVEIN.JAVA in extortion-focused operations.
Referenced as a financially motivated threat actor associated with increased use of zero-day exploits in ransomware operations during 2025.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.