Blog Post

Microsoft Defender for Endpoint Blog
1 MIN READ

Analysis of FinFisher malware used by NEODYMIUM group

Louie Mayor's avatar
Louie Mayor
Icon for Microsoft rankMicrosoft
Mar 02, 2018

 

Office 365 Advanced Threat Protection (Office 365 ATP) blocked many notable zero-day exploits in 2017. In our analysis, one activity group stood out: NEODYMIUM. This threat actor is remarkable for two reasons:

  • Its access to sophisticated zero-day exploits for Microsoft and Adobe software
  • Its use of an advanced piece of government-grade surveillance spyware FinFisher, also known as FinSpy and detected by Microsoft security products as Wingbird

FinFisher is such a complex piece of malware that, like other researchers, we had to devise special methods to crack it.

 

Read the rest of the post

 

Updated Mar 02, 2018
Version 3.0
No CommentsBe the first to comment