Lunar Spider
LUNAR SPIDER, also known as Gold Swathmore, is a Russian-speaking, financially motivated cybercriminal threat actor active since at least 2009. The group is associated with the development and operation of IcedID (also known as BokBot) and Latrodectus, and reporting in the provided content assesses with high confidence that it resumed operations after the May 2024 Operation Endgame disruption. The group has been linked to campaigns targeting the financial sector, including an October 2024 malvertising and SEO-poisoning operation in which victims searching for tax-related content were redirected to an obfuscated JavaScript downloader that retrieved an MSI installer and deployed Brute Ratel C4 via rundll32. The content also links LUNAR SPIDER to FakeCaptcha and ClickFix-style delivery of Latrodectus, and to hands-on-keyboard intrusions in which Latrodectus dropped a BackConnect RAT. That RAT used the same C2 protocol seen in IcedID and QakBot infections and supported reverse VNC, reverse SOCKS, reverse shell, and file-management functionality. The intrusion reporting also noted follow-on deployment of Cobalt Strike and Brute Ratel C4. The provided content states that LUNAR SPIDER acts as an initial access broker for ransomware operators and shares infrastructure and malware services with other cybercrime actors. It very likely provided initial access to WIZARD SPIDER and has reported ties to ALPHV/BlackCat, Nemty, and TA2101/TWISTED SPIDER. The content also notes infrastructure overlap between IcedID and Latrodectus operations, including shared hosting, SSL certificate patterns, use of ASN 395092 (SHOCK-1), and more than 200 malicious infrastructure elements attributed to the group. The group has also been observed abusing Telegram for victim click monitoring on its FakeCaptcha panel delivering Latrodectus, using JavaScript to fingerprint visitors and sending collected information through Telegram's /sendMessage API endpoint. Aliases: LUNAR SPIDER, Gold Swathmore.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
Observables
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lunar Spider is known for using Telegram as a channel for monitoring victim interactions with their FakeCaptcha panel, specifically in campaigns delivering the Latrodectus malware.
Lunar Spider is a Russian-speaking cybercriminal group behind IcedID and Latrodectus malware, using phishing and advanced delivery techniques for malware distribution and long-term intrusions.
Intrusion activity attributed/linked to Lunar Spider using a JavaScript lure (tax form) to deliver Brute Ratel, followed by multi-malware deployment, credential theft, lateral movement, and data exfiltration over an extended dwell time.
Cybercrime group associated with development and deployment of IcedID and Latrodectus; uses web-based social engineering (fake CAPTCHA) to drive malware infections.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.