
Dell SonicWALL Threats Research team received reports of a spying tool being sent as an attachment in spear phishing emails targeting activists. This spying tool called FinFisher/FinSpy has been linked to being covertly used by various governments for surveillance within and across their borders. The tool behaves like a Trojan and uses various stealth techniques to evade detection. It harvests user data and attempts to upload the encrypted data to a remote server.
The executable in the email attachment uses the following misleading icons:
The FinSpy tool when executed performs the following activities:
Dell SonicWALL Gateway AntiVirus provides protection against this threat with the following signatures:
Share This Article

An Article By
An Article By
Security News
Security News