BLOCKADE SPIDER is a financially motivated eCrime threat actor active since at least 2024 and associated with Embargo ransomware operations. The group is notable for cross-domain intrusion tradecraft that spans identity, endpoint, backup, cloud, and virtualized infrastructure, enabling rapid progression from initial compromise to post-compromise objectives. Observed activity includes gaining initial access through unmanaged VPN infrastructure, operating inside enterprise networks, attempting to obtain credentials from backup systems, attempting to delete backups, and interfering with endpoint security tooling. BLOCKADE SPIDER has also been linked to use of the OrBit Linux userland rootkit to maintain stealthy persistence in VMware virtualization environments. OrBit provides persistence by loading into processes system-wide, supports credential theft from authentication activity, and enables defense evasion through extensive userland hooking and concealment. The actor’s operations align with ransomware intrusion patterns focused on access retention, credential abuse, backup disruption, and movement across multiple administrative domains prior to extortion or encryption stages. BLOCKADE SPIDER is widely tracked as an Embargo ransomware actor rather than a state-sponsored espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
eCrime group associated with Embargo ransomware that used the OrBit rootkit to maintain covert persistence in VMware virtualization environments.
eCrime adversary active since at least 2024 that uses the OrBit backdoor for persistence and stealthy access in virtualization environments to support Embargo ransomware operations.
Referenced as a China-backed threat actor noted for targeting unmanaged devices (e.g., VPNs, firewall appliances, personal devices, webcams, third-party apps, VMs) that often lack EDR coverage.
Blockade Spider conducts ransomware and data theft operations using Embargo ransomware, targeting unmanaged systems and cloud environments, and employing cross-domain lateral movement.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.