Exploitation of Windows Finger Command for Malicious File Transfers

Exploitation of Windows Finger Command for Malicious File Transfers

First seen 18 Aug 2026, 15:43 UTC www.bleepingcomputer.comisc.sans.edu 72% similarity 67.5

Article Content

Browse articles
ThreatCluster

Security researchers have identified that the Windows finger.exe command can be exploited to download or steal files, functioning as a living-off-the-land binary (LoLBin). Discovered by John Page, this vulnerability allows attackers to use finger.exe as a makeshift command and control (C2) server, enabling data exfiltration without detection by Windows Defender. The attack method involves encoding files in Base64 to evade security measures and utilizing Windows NetSh Portproxy to bypass firewall restrictions. Organizations using explicit proxies may be safe, but those with transparent proxies could be vulnerable. The threat is compounded by the growing list of LoLBins in Windows, which includes tools like certutil.exe and desktopimgdownldr.exe. Proof-of-concept scripts have been released to demonstrate the exploit's effectiveness. The potential for widespread impact is significant, especially in environments where security measures are lax.

Key Points: • Windows finger.exe can be exploited to download files undetected. • Attackers can use Base64 encoding to evade security measures. • Organizations with transparent proxies may be at risk of exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-08-18
Discovery of finger.exe exploitation
Security researcher John Page revealed that finger.exe can be used as a C2 server for data exfiltration.
BleepingComputer
2026-08-18
Proof-of-concept scripts released
John Page released DarkFinger.py and DarkFinger-Agent.bat to demonstrate the exploit's capabilities.
BleepingComputer
2026-08-18
ClickFix attacks mentioned
The ClickFix attacks utilize finger.exe to retrieve malicious scripts via the finger protocol.
SANS ISC

Community

Browse all →

Tracked Entities in This Story