LUNAR SPIDERLUNAR SPIDER

Also known as: GOLD SWATHMORE · LUNAR SPIDER

Known aliases
2

Profile

According to CrowdStrike, this actor is using BokBok/IcedID, potentially buying distribution through Emotet infections. On March 17, 2019, CrowdStrike Intelligence observed the use of a new BokBot (developed and operated by LUNAR SPIDER) proxy module in conjunction with TrickBot (developed and operated by WIZARD SPIDER), which may provide WIZARD SPIDER with additional tools to steal sensitive information and conduct fraudulent wire transfers. This activity also provides further evidence to support the existence of a flourishing relationship between these two actors. Lunar Spider is reportedly associated withGrim Spider and Wizard Spider.

Aliases· 2

GOLD SWATHMORELUNAR SPIDER

References

  1. https://www.crowdstrike.com/resources/reports/2019-crowdstrike-global-threat-report/
  2. https://www.crowdstrike.com/blog/wizard-spider-lunar-spider-shared-proxy-module/
  3. https://www.crowdstrike.com/blog/sin-ful-spiders-wizard-spider-and-lunar-spider-sharing-the-same-web/
  4. https://www.secureworks.com/research/threat-profiles/gold-swathmore

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
WIZARD SPIDER
Actor
NOCTURNAL SPIDER
Actor
SALTY SPIDER
Actor
BOSON SPIDER
Actor
BOSS SPIDER
Actor
GURU SPIDER
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.