SCULLY SPIDER is a Russia-based eCrime threat actor associated with the development, administration, and operation of the DanaBot malware ecosystem. The group has operated DanaBot as a malware-as-a-service platform, maintaining command-and-control infrastructure and providing malware access to affiliates who conduct their own distribution and follow-on operations. Since emerging in 2018, DanaBot evolved from a banking trojan into a modular criminal platform used for credential theft, keylogging, fraud enablement, covert remote access, malware delivery, and data exfiltration. Reported functionality has included web injects, screen recording, and hidden remote-control capability. SCULLY SPIDER has targeted victims across multiple countries, initially focusing on Ukraine and several European countries before expanding to North America and Australia. Victimology has included financial institutions as well as organizations in transportation, media, technology, and financial services, including through supply-chain compromises involving widely used software packages. Between 2018 and 2021, the actor increasingly used DanaBot as a distribution platform for additional malware, demonstrating a shift from single-purpose banking fraud toward broader criminal access operations. The group has also been linked to activity aligned with Russian state interests. DanaBot infrastructure and sub-botnets were reportedly used in support of espionage operations, and in 2022 a DanaBot sub-botnet was tasked to facilitate HTTP-based distributed denial-of-service attacks against Ukrainian government targets shortly after Russia’s full-scale invasion of Ukraine. This combination of financially motivated cybercrime, malware-as-a-service operations, and state-aligned tasking makes SCULLY SPIDER a notable hybrid threat actor. Since 2022, SCULLY SPIDER has reportedly continued to adapt both its business model and malware codebase, including annual restructuring of service offerings and ongoing refactoring intended to improve defense evasion and sustain operational utility for both criminal customers and state-linked use cases. The actor is also listed among Russian-aligned cybercriminal groups assessed as potential threats to critical infrastructure organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
10 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in global threat reporting.
Russian cybercriminal group highlighted in the alert as part of the broader Russian cyber threat landscape.
Russian cybercrime group named in the alert as a threat to foreign targets and critical infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.