Filemon - Tool

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
November 15, 2025
Last Seen
November 17, 2025

Filemon is an attack tool used by the ClickFix malware campaigns.

Overview

Filemon is an attack tool used by the ClickFix malware campaigns. It leverages the decades-old finger protocol/command to perform reconnaissance and discovery, illustrating how threat actors repurpose legacy technologies to evade modern defenses and expand access.

Related Threat Clusters

  • Revival of Finger Command in ClickFix Malware Attacks

    Threat actors are exploiting the decades-old 'finger' command in new ClickFix malware attacks to execute remote commands on Windows devices. The command, which was historically used to retrieve user information on Unix…

    4 articles · Updated November 17, 2025
  • Revival of 'Finger' Command in ClickFix Malware Attacks

    Threat actors have reintroduced the decades-old 'finger' command in new ClickFix malware attacks to facilitate remote command execution on Windows devices. The command, originally used for user information retrieval on…

    2 articles · Updated November 17, 2025

Recent Intelligence Reports

  • New ClickFix attacks reuse ancient 'finger' command — Scworld · November 17, 2025
  • Decades-old ‘Finger’ protocol abused in ClickFix malware attacks — Bleepingcomputer · November 15, 2025

CVSS v3.1 Breakdown