Final
- Malware type
- ransomware
- Profile updated
- 2026-07-07 16:17:08
Targeted industries: financial-services healthcare-and-pharmaceutical education-and-nonprofits
Context
Final is a ransomware that encrypts files on the victim's machine, demanding a ransom for decryption. It targets various industries, impacting operations significantly by denying access to critical data until a ransom is paid.
Detection coverage
- 6 YARA rules
Used by threat actors
- Emmenhtal Loader Distribution Activity (campaign)
Detection rules
- ARKBIRD_SOLG_APT_MAL_Donot_Loader_June_2020_1 (yara-rule)
- SECUINFRA_MAL_Nw0Rm (yara-rule)
- SEKOIA_Plugx_Final_Payload (yara-rule)
- SIGNATURE_BASE_MAL_PHISH_Final_Payload_Feb25 (yara-rule)
- SIGNATURE_BASE_APT_MAL_Sidewinder_Implant (yara-rule)
- SIGNATURE_BASE_MAL_JAVA_Loader_Final_Jar_Aug25 (yara-rule)