logo

Can’t Touch This: Data Exfiltration via Finger

ID: 01d75d74-3216-5b68-b38e-5f7891eba283

STIX ID: report--01d75d74-3216-5b68-b38e-5f7891eba283

Feed Name: Huntress Blog

Threat Score
55/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress observed threat actors leveraging the native Windows finger.exe utility to download files and exfiltrate unencrypted data from a compromised MS Exchange server (example commands and an associated malicious IP 185.56.83.82 are provided); the report maps the activity to MITRE ATT&CK techniques (T1105, T1048.003) and recommends monitoring or removing unused LOLBins and tuning detection to identify such abuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.