Renaissance Spider is a financially motivated eCrime threat actor based in the Russian Federation. The group has been observed since at least 2019, with some reporting placing activity as early as 2017. It is associated with malspam campaigns and targeted intrusion operations, and has also been linked to influence and sabotage activity conducted through inauthentic hacktivist personas, including DaVinci Group and Fire Cells Group. Reporting further associates the actor with coordinated physical intimidation and disruption activity in Europe, including fake bomb threats, in operations assessed as intended to undermine support for Ukraine. Renaissance Spider has demonstrated adaptation of social-engineering tradecraft, including use of AI to translate ClickFix lures into Ukrainian. The actor has also been identified as shifting attention toward Latin America in 2024. Available reporting supports a primarily criminal, financially motivated profile, while also indicating overlap with disruptive and influence-oriented operations aligned with Russian interests. Known aliases directly supported here are limited to Renaissance Spider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-based financially motivated cybercrime group using AI to localize/translate ClickFix social-engineering lures (e.g., fake CAPTCHA themes) to improve targeting effectiveness.
Russia-based financially motivated eCrime actor (mid-2019) using malspam and targeted intrusions; also conducts influence/sabotage via inauthentic hacktivist personas.
Renaissance Spider is a Russia-affiliated cybercriminal group involved in both digital and physical extortion, including ransomware, violence-as-a-service, and psychological operations such as fake bomb threats.
Financially motivated threat group described as Russia-linked that began shifting attention to Latin America in 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.