Home/Threat Actor/FinFisher (FinSpy / Gamma Group)
Threat Actor

FinFisher (FinSpy / Gamma Group)

finfisher_finspy · uk_germany_commercial_spyware_vendor_dissolved · active since 2008-01

FinFisher (also known as FinSpy) is a longstanding commercial spyware vendor product family marketed by Lench IT Solutions plc with UK-based Gamma International Ltd (Andover, England) parent and Germany-based Gamma International GmbH (Munich) operations, operational ~2008-March 2022 as longest-lifecycle commercial spyware vendor in cell with reported British Virgin Islands shell- corporation ownership via William Louthean Nelson; UK-Germany PSOA attribution via Citizen Lab / University of Toronto / Bill Marczak / Morgan Marquis-Boire canonical 2012-2015 longstanding tracking + 33-government suspected-use October 2015 research (including Egypt + Bahrain + Ethiopia + Turkey + Myanmar + Saudi Arabia + Venezuela + Sudan + Lebanon + UAE + Oman + Morocco + Bangladesh) + Wikipedia + Bloomberg / Lorenzo Franceschi-Bicchierai March 2022 insolvency disclosure + Netzpolitik original reporting + RSF Germany / Katja Gloger + Gesellschaft für Freiheitsrechte GFF / Sarah Lincoln + European Centre for Constitutional and Human Rights ECCHR / Miriam Saage-Maaß + Munich Public Prosecutor's Office / Anne Leiding + Phineas Fisher August 6 2014 40GB breach + Access Now + The Record + ESET 2018 post-leak analysis + Bahrain Watch + Masaar + EDRi + Gizmodo + TheProjectCounselGroup industry coverage.

standalone cluster paralleling dsirf_knotweed + variston_heliconia + hacking_team_memento_labs in v0.1.163 commercial spyware / mercenary surveillance vendor operators cell continuation.

operational target profile 33+ government suspected-client customer base per Citizen Lab October 2015 + signature German BND Bundesnachrichtendienst licensed per 7 December 2012 Federal Ministry of Interior document + Turkish MIT intelligence signature 2017 Kılıçdaroğlu campaign + Ethiopian government per American citizen lawsuit + Bahraini activists per 2012 Citizen Lab + 2014 Bahrain Watch leak analysis + Egyptian dissidents + State Security Investigations Service Arab Spring exposure + Myanmar + Turkey + Egypt continued usage post-2015-export-restriction per ECCHR.

operational attack architecture: (1) cluster-defining FinSpy state trojan multi- platform payloads with Windows + Mac + Linux + Android + iOS + BlackBerry + Symbian + Windows Mobile + Windows Phone class operating system coverage.

(2) cluster-defining 2008 iTunes update procedure exploitation vector first described by security commentator Brian Krebs with Apple not patching for 3+ years until November 2011.

(3) cluster-defining March 2011 Arab Spring Egyptian SSI State Security Investigations Service €287,000 Gamma International UK Ltd June 2010 invoice exposure during dissident raid on State Security office with documents revealing 5-month trial version usage providing first major public exposure; (4) cluster-defining August 6, 2014 Phineas Fisher 40GB breach with FinFisher source code + pricing + support history + internal documents revealed providing operational intelligence to security researchers for ~8 years prior to insolvency; (5) cluster-defining 2017 Turkey Kılıçdaroğlu opposition campaign website fake-version targeting ("In summer 2017, FinSpy was detected on a Turkish website designed to lure members of the Turkish opposition movement headed by then presidential candidate Kemal Kılıçdaroğlu") signature export- without-German-authorization violation that triggered subsequent criminal complaint.

(6) cluster-defining July 5, 2019 RSF + GFF + ECCHR + netzpolitik criminal complaint alleging CEOs of FinFisher GmbH + FinFisher Labs GmbH + Elaman GmbH sold FinSpy to Turkey without German federal government authorisation.

(7) cluster-defining October 2020 Munich + Germany + Romania raids + account seizure by Munich Public Prosecutor's Office.

(8) cluster-defining March 2022 insolvency filing with FinFisher GmbH + FinFisher Labs GmbH + raedarius m8 GmbH filing for insolvency via JAFFÉ Rechtsanwälte Insolvenzverwalter administrator with employees no longer employed + business premises abandoned + Munich location dissolved.

(9) cluster-defining May 2023 Munich Public Prosecutor's Office charges against 4 corporate executives establishing individual-accountability outcome from ~4-year investigation.

(10) signature UEFI bootkit + 4-layer obfuscation + advanced anti- analysis measures late-period evolution with non-persistent pre-validator (anti-research) + post- validator (victim-verification) two-component design ensuring only intended victims receive full Trojan deployment.

(11) signature VMProtect obfuscation + Scout + Soldier payload naming continuity post- leak per ESET 2018 analysis with samples compiled September 2015 - October 2017 + same compilation patterns continuing from pre-leak development practices establishing continued operations post- 2014-breach.

(12) signature multi-platform capability hack target phones + computers + networks + internet-connected devices + remote camera + microphone activation + live surveillance + Skype/calls + chats + photos + location data + cryptocurrency wallets capabilities.

(13) signature Vilicius Holding GmbH successor restructuring entity per Wikipedia documentation suggesting potential continued operations under different name.

cluster fills the UK-Germany-PSOA + Lench-IT- Solutions-Gamma-Group-corporate-structure + FinSpy- state-trojan-product + Arab-Spring-2011-Egyptian- SSI-€287000-invoice + Phineas-Fisher-2014-40GB- breach + 33-governments-Citizen-Lab-October-2015 + 2017-Turkey-Kılıçdaroğlu-campaign-targeting + July- 2019-RSF-GFF-ECCHR-netzpolitik-criminal-complaint + October-2020-Munich-raids + March-2022-insolvency- filing + May-2023-charges-4-corporate-executives + UEFI-bootkit-4-layer-obfuscation-late-period- evolution position in commercial spyware / mercenary surveillance vendor operators cell; canonical illustration of longest-lifecycle commercial spyware vendor (14+ years operational) + state-trojan product + 33+ government customer base + Arab Spring authoritarian-regime customer pattern + Phineas Fisher vigilante-exposure + civil-society-driven accountability via RSF + GFF + ECCHR + netzpolitik criminal complaint + Munich prosecutor accountability culminating in March 2022 insolvency + May 2023 executive charges cited in essentially all subsequent commercial spyware accountability industry analyses through 2008-2026 period.

uk_germany_commercial_spyware_vendor_dissolved confidence: high 25 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

FinFisher (also known as FinSpy) is a longstanding commercial spyware vendor product family marketed by Lench IT Solutions plc with UK-based Gamma International Ltd (Andover, England) parent and Germany-based Gamma International GmbH (Munich) operations, operational ~2008-March 2022 as longest- lifecycle commercial spyware vendor in cell. UK-Germany PSOA attribution via Citizen Lab canonical 2012-2015 longstanding tracking + 33- government suspected-use October 2015 research + Wikipedia + Bloomberg + Netzpolitik + RSF + GFF + ECCHR + Phineas Fisher August 2014 40GB breach + Access Now + The Record + Gizmodo + ESET 2018 post-leak analysis + Munich Public Prosecutor's Office canonical investigation documentation. Operations terminated March 2022 insolvency filing FinFisher GmbH + FinFisher Labs GmbH + raedarius m8 GmbH following October 2020 Munich + Germany + Romania raids + account seizure triggered by July 5 2019 RSF + GFF + ECCHR + netzpolitik criminal complaint over illegal Turkey export.

May 2023 charges against 4 corporate executives. Standalone cluster paralleling dsirf_knotweed + variston_heliconia + hacking_team_memento_labs in v0.1.163 commercial spyware / mercenary surveillance vendor operators cell continuation.

Operational target profile
  • 33+ governments suspected client per Citizen Lab October 2015 including Egypt + Bahrain + Ethiopia + Turkey + Myanmar + Saudi Arabia + Venezuela + Sudan + Lebanon + UAE + Oman + Morocco + Bangladesh.
  • German BND Bundesnachrichtendienst licensed per 2012 document.
  • Turkish MIT signature 2017 Kılıçdaroğlu targeting.
  • Dissidents + activists + journalists + human rights defenders signature targets Operational attack architecture: (1) FinSpy state trojan multi-platform (cluster- defining): Windows + Mac + Linux + Android + iOS + BlackBerry + Symbian payloads (2) 2008 iTunes update procedure exploitation vector (cluster-defining): 3+ years unpatched flaw (3) 2011 Arab Spring Egyptian SSI €287,000 invoice exposure (cluster-defining): first major public exposure (4) 2014 Phineas Fisher 40GB breach (cluster- defining): vigilante-hacker exposure with source code leak (5) 2017 Turkey Kılıçdaroğlu opposition campaign website fake-version (cluster-defining): signature authoritarian-regime customer targeting (6) 2019 RSF + GFF + ECCHR + netzpolitik criminal complaint (cluster-defining): civil-society- driven accountability mechanism (7) 2020 Munich + Germany + Romania raids (cluster-defining) (8) March 2022 insolvency filing (cluster- defining): operational-end (9) May 2023 4-executive charges (cluster- defining): individual accountability outcome (10) UEFI bootkit + 4-layer obfuscation + pre- validator + post-validator late-period evolution (signature) (11) VMProtect obfuscation + Scout + Soldier payload naming continuity post-leak per ESET 2018 (signature) The cluster fills the UK-Germany-PSOA + Lench-IT- Solutions-Gamma-Group-corporate-structure + FinSpy- state-trojan-product + Arab-Spring-2011-Egyptian- SSI-€287000-invoice + Phineas-Fisher-2014-40GB- breach + 33-governments-Citizen-Lab-October-2015 + 2017-Turkey-Kılıçdaroğlu-campaign-targeting + July- 2019-RSF-GFF-ECCHR-netzpolitik-criminal-complaint + October-2020-Munich-raids + March-2022-insolvency- filing + May-2023-charges-4-corporate-executives + UEFI-bootkit-4-layer-obfuscation-late-period- evolution position in commercial spyware / mercenary surveillance vendor operators cell.

Aliases

25
finfisher_finspyfinfisherfinspyfinfisher gmbhfinfisher labs gmbhraedarius m8 gmbhvilicius holding gmbhgamma_groupgamma international ltd andovergamma international gmbh munichlench it solutions plcelaman_gmbhtrovicor_gmbhfinfisher gamma international andover england munich germanyfinfisher arab spring 2011 egyptian ssi state security investigationsfinfisher €287,000 egyptian secret police invoicefinfisher phineas fisher 2014 400gb breachfinfisher 33 governments citizen lab 2015finfisher 2017 turkey opposition kılıçdaroğlu campaign websitefinfisher july 2019 rsf gff ecchr netzpolitik criminal complaintfinfisher october 2020 munich raids account seizurefinfisher march 2022 insolvency filing dissolutionfinfisher may 2023 charges 4 corporate executives munichfinfisher uefi bootkit 4-layer obfuscation advanced anti-analysisfinfisher pre-validator post-validator two-component design

Notable Campaigns

11
2023FinFisher May 2023 Munich Public Prosecutor's Office Charges Against 4 Corporate Executives
2022FinFisher March 2022 Insolvency Filing Dissolution
2020FinFisher October 2020 Munich + Germany + Romania Raids + Account Seizure
2019-2021FinFisher UEFI Bootkit + 4-Layer Obfuscation Late-Period Evolution Signature
2019FinFisher July 5, 2019 RSF + GFF + ECCHR + netzpolitik Criminal Complaint Signature
2017FinFisher 2017 Turkey Kılıçdaroğlu Opposition Campaign Website Targeting Signature
2015FinFisher Citizen Lab October 2015 33 Governments Suspected-Use Report
2014FinFisher Phineas Fisher August 6, 2014 40GB Breach
2011FinFisher Arab Spring 2011 Egyptian SSI €287,000 Invoice Exposure
2008-2026Continued Industry Reference Status (2008-2026)
2008FinFisher Origin, 2008 Gamma Group Subsidiary Emergence

Attribution & Reporting

Attributed by
Citizen Lab / University of Toronto / Bill Marczak / Morgan Marquis-Boire (canonical 2012-2015 longstanding FinFisher tracking + 33-government suspected-use research October 2015)Wikipedia (canonical longstanding 2008-2024 tracking)Bloomberg (canonical March 2022 insolvency disclosure via Lorenzo Franceschi-Bicchierai)Netzpolitik (canonical German tech news + March 2022 insolvency original reporting + RSF criminal complaint co-filer)Reporters Without Borders Germany RSF (canonical July 5 2019 criminal complaint + ongoing tracking)Gesellschaft für Freiheitsrechte (GFF) / Sarah Lincoln + Society for Civil Rights (canonical criminal complaint coordinator)European Centre for Constitutional and Human Rights (ECCHR) / Miriam Saage-Maaß (canonical criminal complaint co-filer + 2013 OECD complaint origin tracking)Munich Public Prosecutor's Office / Anne Leiding (canonical 2019-2023 investigation + charges)Access Now (canonical 2018 FinFisher discovery report + March 2022 shutdown documentation)Phineas Fisher (canonical August 6 2014 40GB FinFisher breach attribution)Bahrain Watch (canonical 2014 leak data Bahraini government surveillance analysis)ESET (canonical March 2018 post-leak FinFisher samples ITW analysis)Masaar (canonical November 2023 Gamma Group analysis)The Record / Recorded Future News (canonical March 2022 insolvency coverage)TheProjectCounselGroup / Berlin (canonical April 2022 FinFisher creepiest spyware companies coverage)Gizmodo / Lucas Ropek (canonical March 2022 Creepy Spyware Company Goes Broke coverage)European Digital Rights (EDRi) (canonical April 2022 criminal complaint impact coverage)Silicon Republic (canonical FinFisher coverage)
Key reporting
reportCitizen Lab / University of Toronto / Bill Marczak / Morgan Marquis-Boire: canonical 2012-2015 longstanding FinFisher tracking + 33-government suspected-use research October 2015
reportWikipedia: canonical longstanding 2008-2024 tracking
reportBloomberg / Lorenzo Franceschi-Bicchierai: canonical March 2022 insolvency disclosure
reportNetzpolitik: canonical German tech news + March 2022 insolvency original reporting
reportRSF Germany / Katja Gloger: canonical July 5 2019 criminal complaint + ongoing tracking
reportGesellschaft für Freiheitsrechte (GFF) / Sarah Lincoln: canonical criminal complaint coordinator
reportEuropean Centre for Constitutional and Human Rights (ECCHR) / Miriam Saage-Maaß: canonical criminal complaint co-filer + 2013 OECD complaint origin tracking
reportMunich Public Prosecutor's Office / Anne Leiding: canonical 2019-2023 investigation + charges
reportAccess Now: canonical 2018 FinFisher discovery report + March 2022 shutdown documentation
reportPhineas Fisher: canonical August 6 2014 40GB FinFisher breach
reportBahrain Watch: canonical 2014 leak data Bahraini government surveillance analysis
reportESET (March 2018): canonical post-leak FinFisher samples ITW analysis
reportMasaar: canonical November 2023 Gamma Group analysis
reportEDRi: canonical April 2022 criminal complaint impact coverage
reportGizmodo / Lucas Ropek: canonical March 2022 Creepy Spyware Company Goes Broke
reportTheProjectCounselGroup / Berlin: canonical April 2022 coverage

Operational

State sponsor

FinFisher GmbH (Munich) + FinFisher Labs GmbH + raedarius m8 GmbH (Munich corporate group) was a commercial spyware vendor with UK-based Gamma International Ltd (Andover, England) parent and Germany-based Gamma International GmbH (Munich) operations. Marketed FinSpy / FinFisher as a "state trojan" / "Lawful Intercept" product to police + intelligence agencies worldwide. Reportedly owned through shell corporation structure via William Louthean Nelson in British Virgin Islands.

Operations terminated March 2022 via insolvency filing following Munich Public Prosecutor's Office account seizure + investigation. Honest attribution caveat: Vilicius Holding GmbH successor entity restructuring filing may indicate continued operations under different name. Operational mission objective: Long-term commercial spyware development + distribution to government law-enforcement + intelligence-agency clients globally.

Per operational characterization: "to access target computer systems around the world" with capability to "hack computers and phones, bypassing anti- virus tools to carry out 'live surveillance' of a person by secretly watching and listening to them through their own camera and microphone." Attribution chain: (1) Wikipedia canonical longstanding tracking: per Wikipedia: "FinFisher, also known as FinSpy, is surveillance software marketed by Lench IT Solutions plc, which markets the spyware through law enforcement channels. FinFisher can be covertly installed on targets' computers by exploiting security lapses in the update procedures of non- suspect software... Lench IT Solutions plc has a UK-based branch, Gamma International Ltd in Andover, England, and a Germany-based branch, Gamma International GmbH in Munich.

Gamma International is a subsidiary of the Gamma Group, specializing in surveillance and monitoring, including equipment, software, and training services. It was reportedly owned by William Louthean Nelson through a shell corporation in the British Virgin Islands." (2) Citizen Lab canonical longstanding 2012-2015 tracking: per Wikipedia + Masaar + ECCHR: "A similar report in August 2012 concerned e-mails received by Bahraini activists and passed on (via a Bloomberg News reporter) to University of Toronto computer researchers Bill Marczak and Morgan Marquis-Boire in May 2012. Analysis of the e-mails revealed code (FinSpy) designed to install spyware on the recipient's computer...

Another report of the same organization in October 2015 revealed suspicions that 33 governments use FinSpy including Egypt, Lebanon, Morocco, Oman, and Saudi Arabia." (3) Arab Spring 2011 Egyptian SSI invoice canonical exposure: per Wikipedia + Masaar: "FinFisher's wide use by governments facing political resistance was reported in March 2011 after Egyptian protesters raided State Security Investigations Service and found letters from Gamma International UK Ltd., confirming that SSI had been using a trial version for five months... One of the documents included an offer from the UK branch dated June 2010, for selling FinSpy to the Egyptian security for 287,000 Euro." (4) Phineas Fisher canonical August 6 2014 breach attribution evidence: per Wikipedia: "On August 6, 2014, FinFisher source code, pricing, support history, and other related data were leaked after the Gamma International internal network was hacked by Phineas Fisher." Per ECCHR: "In 2014, an American citizen sued the Ethiopian government for surreptitiously installing FinSpy onto his computer in America and using it to wiretap his private Skype calls and monitor his entire family's every use of the computer for a period of months." (5) September 2019 + 2022-2023 RSF + GFF + ECCHR + netzpolitik criminal complaint canonical attribution chain: per RSF + ECCHR + EDRi: "The criminal complaint that RSF Germany, the Society for Civil Rights (Gesellschaft für Freiheitsrechte, GFF), the European Centre for Constitutional and Human Rights (ECCHR) and netzpolitik.org filed on 5 July 2019 alleged that the CEOs of FinFisher GmbH, FinFisher Labs GmbH, and Elaman GmbH sold the spyware FinSpy to Turkey without the German federal government's authorisation." Per ECCHR: "In March 2022, FinFisher, the manufacturer of the spyware, had to file for bankruptcy following a criminal complaint by the Gesellschaft für Freiheitsrechte (GFF), Reporters Without Borders (RSF Germany), the blog netzpolitik.org and ECCHR. In May 2023, the Munich Public Prosecutor's Office brought charges against four managers of the corporate group." (6) Bloomberg + Netzpolitik canonical March 2022 insolvency disclosure: per Bloomberg via The Project Counsel Group + Access Now + The Record: "In early February, Munich-based FinFisher and two related firms, FinFisher Labs GmbH and raedarius m8 GmbH, filed for insolvency, according to the German insolvency administrator JAFFÉ Rechtsanwälte Insolvenzverwalter. 'Employees are no longer employed in the companies,' a spokesman for the administrator said in a statement to Bloomberg News. 'The business premises were abandoned in the course of the opening of insolvency proceedings and the location of the companies in Munich was dissolved, as there was no perspective of continuing business operations.'" (7) 2017 Turkey opposition Kılıçdaroğlu campaign canonical attack signature: per RSF: "In summer 2017, FinSpy was detected on a Turkish website designed to lure members of the Turkish opposition movement headed by then presidential candidate Kemal Kılıçdaroğlu.

It may have enabled the surveillance of many political activists and journalists. The Turkish intelligence agency MIT can use the spyware to locate individuals, record their telephone calls and chats and see all the data on mobile phones and computers." (8) ESET 2018 post-leak Hacking Team-style continued-operations evidence: per ESET: analyzing post-2015-leak FinFisher samples compiled between September 2015 and October 2017 with VMProtect obfuscation + same compilation patterns + Scout + Soldier payload naming continuing from pre-leak development practices.

Operational target profile
  • 33+ governments suspected client per Citizen Lab October 2015 including Egypt + Bahrain + Ethiopia + Turkey + Myanmar + Saudi Arabia + Venezuela + Sudan + Lebanon + UAE + Oman + Morocco + Bangladesh.
  • German Bundesnachrichtendienst (Federal Surveillance Agency) licensed FinFisher/FinSpy per 7 December 2012 Federal Ministry of Interior document.
  • Turkish MIT intelligence agency signature per 2017 Kılıçdaroğlu campaign + Turkish dissident surveillance.
  • Ethiopian government signature per American citizen lawsuit + Skype call wiretapping.
  • Bahraini activists signature per 2012 Citizen Lab + 2014 Bahrain Watch leak analysis.
  • Egyptian dissidents + State Security Investigations Service signature.
  • Myanmar + Turkey + Egypt continued usage post-2015-export-restriction per ECCHR The cluster fills the UK-Germany-PSOA + Lench-IT- Solutions-Gamma-Group-corporate-structure + FinSpy- state-trojan-product + Arab-Spring-2011-Egyptian- SSI-€287000-invoice + Phineas-Fisher-2014-40GB- breach + 33-governments-Citizen-Lab-October-2015 + 2017-Turkey-Kılıçdaroğlu-campaign-targeting + July- 2019-RSF-GFF-ECCHR-netzpolitik-criminal-complaint + October-2020-Munich-raids + March-2022-insolvency- filing + May-2023-charges-4-corporate-executives + UEFI-bootkit-4-layer-obfuscation-late-period- evolution position in commercial spyware / mercenary surveillance vendor operators cell.
Motivations
uk_germany_commercial_spyware_vendor_revenue, government_law_enforcement_intelligence_agency_customer_target_market, finspy_state_trojan_product_development_distribution, turkey_export_without_authorization_signature_violation, long_term_arab_spring_post_arab_spring_authoritarian_regime_customer_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)29/60 · 48%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MICROSOFT WORD DOCUMENT ATTACHMENT ETHIOPIA 2014SCOUT PAYLOAD PRE-LEAK HACKING TEAM-STYLE NAMINGSOLDIER PAYLOAD PRE-LEAK HACKING TEAM-STYLE NAMING
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin