TRAVELING SPIDER is a financially motivated cybercriminal group that operates ransomware-as-a-service (RaaS). It is associated with Nemty, including Nemty X, and its affiliate activity has included deployment of INC ransomware against Windows systems and VMware ESXi hypervisors. The group participates in ransomware extortion campaigns in the Asia Pacific and Japan region. It maintains an affiliation with LUNAR SPIDER and has leveraged that actor's IcedID malware for initial access. Its historical social-engineering activity includes COVID-19-themed campaigns impersonating healthcare organizations. Affiliate intrusion techniques include initial access through internet-exposed FortiGate VPN appliances, lateral movement using RDP, and remote execution through WinRM. Reconnaissance uses Advanced IP Scanner and PowerShell to enumerate reachable systems, Active Directory computers, network shares, and storage locations. Affiliates have added accounts to Domain Admins groups, altered file ownership and permissions across drive volumes, and enabled RDP Restricted Admin mode to facilitate credential theft and lateral movement. Data theft precedes ransomware deployment, with Rclone used to transfer business documents, email data, CAD files, and other sensitive information to Wasabi S3 storage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware activity leveraging COVID-19-themed lures; impersonates healthcare organizations as part of pandemic-related campaigns.
Ransomware group referenced as affiliated with Lunar Spider and leveraging IcedID for initial access.
A ransomware-as-a-service operation whose affiliate conducted at least five intrusions from February to April 2026. The affiliate accessed internet-exposed FortiGate VPN appliances, moved laterally through RDP and WinRM, performed Active Directory and network-share reconnaissance, exfiltrated data with Rclone to Wasabi S3 buckets, and deployed INC ransomware against VMware ESXi and Windows systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.