Circus Spider is a financially motivated eCrime threat actor associated with NetWalker ransomware operations. The actor is known for targeting healthcare organizations, particularly hospitals, and has been linked to activity against victims in the United States and Spain. NetWalker activity attributed to Circus Spider was part of the broader 2020 surge in big-game-hunting ransomware and pandemic-themed criminal operations. Circus Spider used ransomware for extortion and was associated with campaigns that leveraged COVID-19-related themes. The actor has been observed targeting healthcare entities during the pandemic period, when ransomware operators increasingly sought to exploit operational pressure on medical organizations. Reported behavior includes attacks intended to disrupt victim operations and coerce payment through ransomware deployment. Circus Spider is also associated with the broader trend of criminal actors using social engineering and sector-focused targeting to improve initial access and victim conversion. The actor is primarily tracked under the alias Circus Spider and is best known for operating behind NetWalker ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.