Finfish malware family
Finfish is a malware family tracked by MalwareAnalyzer by Cyble across 13 publicly analyzed samples. First seen 2026-08-09, most recently 2026-08-23. Observed ATT&CK techniques include T1543.003, T1112, T1059.001.
Corpus statistics
- Publicly analyzed samples: 13
- First seen: 2026-08-09
- Last seen: 2026-08-23
- Verdicts: malicious 13
- File types: pe 13
ATT&CK techniques used by Finfish
Recent Finfish samples
- 0901b477cab1beb5cc72169fe69169b11773f6ab1f5ef28e9b9981b56d940338 - malicious (2026-08-23)
- 2e8a4ea09616a6e479cdf186055e9a9ae4ea6182a3c839d35aa46a80ac362cce - malicious (2026-08-22)
- 05a208e7f396c42d5f955867ee6eec83a6b690e09288fee523cdd1ddb3b436bd - malicious (2026-08-22)
- af536f94c27f72452557f6ce3e2adf2b270750b101b00424d29895b9fe8605c7 - malicious (2026-08-21)
- 8903aec30042e9538dbabe16431c98ea409021c16270ea43b9dc9c5d4f18553f - malicious (2026-08-20)
- cb535840a658934ffb2c7ca6cfb59c6ca0bdf27e7c3b47f41a8652270abd22ea - malicious (2026-08-16)
- 8a51d21507fb28369ecfa991f030d86b31fc7edfd58d4e4646cd1788ad0f582f - malicious (2026-08-15)
- 463fd094c8ffe90d64f075824930d0f14946c8cd2f35408405e7a0db8a406072 - malicious (2026-08-15)
- ef967e5e3610bd3ff759ce4569d85d2a0617f59527ab01aa7e750013101a5be6 - malicious (2026-08-14)
- 2dff7181d81d70b6964a37701560730e307b8711ca20fba2a594724d59e0ed61 - malicious (2026-08-14)
- 1b246faa89bd70ec136737f55b63ae1988fca27314bf1c84da4b623639ca616f - malicious (2026-08-13)
- virussign.com_81110be1a32d25848bb120d0bec63a30.vir - malicious (2026-08-13)
- c592878c7a5a9f3fc7b4e645e8b45f984d16de302a8a94bfc365a99c232eda0e - malicious (2026-08-09)
Frequently asked about Finfish
- What is Finfish?
- Finfish is a malware family tracked by MalwareAnalyzer by Cyble across 13 publicly analyzed samples. First seen 2026-08-09, most recently 2026-08-23. Observed ATT&CK techniques include T1543.003, T1112, T1059.001.
- How many Finfish samples have been analyzed?
- MalwareAnalyzer by Cyble holds 13 publicly analyzed samples attributed to Finfish, first seen 2026-08-09 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Finfish use?
- Across our Finfish samples the most frequently observed techniques are T1543.003 (6), T1112 (2), T1059.001 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Finfish use?
- Finfish samples in this corpus are distributed as pe (13).
- Is Finfish malicious?
- 13 of 13 analyzed Finfish samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends