PINCHY SPIDERPINCHY SPIDER

Also known as: PINCHY SPIDER

Known aliases
1

Profile

First observed in January 2018, GandCrab ransomware quickly began to proliferate and receive regular updates from its developer, PINCHY SPIDER, which over the course of the year established a RaaS operation with a dedicated set of affiliates. CrowdStrike Intelligence has recently observed PINCHY SPIDER affiliates deploying GandCrab ransomware in enterprise environments, using lateral movement techniques and tooling commonly associated with nation-state adversary groups and penetration testing teams. This change in tactics makes PINCHY SPIDER and its affiliates the latest eCrime adversaries to join the growing trend of targeted, low-volume/high-return ransomware deployments known as “big game hunting.” PINCHY SPIDER is the criminal group behind the development of the ransomware most commonly known as GandCrab, which has been active since January 2018. PINCHY SPIDER sells access to use GandCrab ransomware under a partnership program with a limited number of accounts. The program is operated with a 60-40 split in profits (60 percent to the customer), as is common among eCrime actors, but PINCHY SPIDER is also willing to negotiate up to a 70-30 split for “sophisticated” customers.

Aliases· 1

PINCHY SPIDER

References

  1. https://www.crowdstrike.com/resources/reports/2019-crowdstrike-global-threat-report/
  2. https://www.crowdstrike.com/blog/pinchy-spider-adopts-big-game-hunting/
  3. https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2020CrowdStrikeGlobalThreatReport.pdf

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
GOLD GARDEN
Actor
GRIM SPIDER
Actor
INDRIK SPIDER
Actor
DOPPEL SPIDER
Group
GOLD SOUTHFIELD
Software
GandCrab
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.