FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines

Posted on Mar 2, 2018

FinFisher exposed: A researcher’s tale of defeating traps, tricks, and complex virtual machines

FinFisher is such a complex piece of malware that, like other researchers, we had to devise special methods to crack it. We needed to do this to understand the techniques FinFisher uses to compromise and persist on a machine, and to validate the effectiveness of Office 365 ATP detonation sandbox, Windows Defender Advanced Threat Protection (Windows Defender ATP) generic detections, and other Microsoft security solutions.

Source: microsoft.com