Spyder is a modular Windows backdoor associated with PRC-linked cyber-espionage activity and most consistently linked to APT41 and the related FishMonger/RedHotel intrusion clusters within the broader Winnti ecosystem. It has been observed alongside other China-aligned tooling including ShadowPad, Winnti, PlugX, Cobalt Strike, FunnySwitch, SodaMaster, and bespoke loaders, indicating use in targeted post-compromise operations rather than commodity crime.
Spyder is used to provide persistent remote access to victim environments and has appeared in intrusions against government, academic, religious, media, telecommunications, research, and other strategic organizations, with notable concentration in Asia and Southeast Asia but broader global victimology as well. It has been documented in operations against Hong Kong universities and in the 2022 FishMedley espionage campaign, where operators deployed Spyder after gaining access to victim networks.
Available reporting supports classifying Spyder as a backdoor implant. It is described as modular, and multiple sources explicitly refer to it as a backdoor. Research also notes similarities between Spyder and Winnti 4.0 Worker in command-handling logic, leading to the hypothesis that Spyder may represent a lighter-weight derivative or related implementation within the same development lineage, although that relationship is not conclusively established.
Observed tradecraft shows Spyder being delivered through loader chains and used after initial compromise. In at least one documented intrusion, a Spyder loader was staged from a compromised internal web server and then executed on the victim host. Broader reporting on the associated actors shows frequent use of DLL side-loading and other stealthy execution methods, but those mechanisms cannot be attributed to Spyder itself with high confidence in every case. Spyder communications have been linked to infrastructure also identified as ShadowPad command-and-control infrastructure, suggesting operational overlap or shared infrastructure management among PRC-linked operators.
Spyder should be understood as an espionage-oriented remote access implant used by China-aligned threat actors for long-term access and follow-on operations in targeted networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Spyder and ReverseWindow are APT malware utilized by PRC-linked cyber espionage threat actors (respectively APT41 and LuoYu).
Their toolkit includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, and the BIOPASS RAT, and expanding SprySOCKS to Windows clearly shows continued investment in offensive capability.
"We also found some similarities between this Trojan and the Spyder downloader used by Maha Grass."
7 distinct techniques documented for this family, organized by ATT&CK tactic.
For years, I have reversed the C2 protocols of high-profile APT malware families then, by emulating the protocols, discovered the active C2 servers on the Internet... both pieces of malware support multiple C2 protocols, such as TCP / TLS / HTTP / HTTPS / UDP.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of FishMonger’s toolkit.
FishMonger’s toolset includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, SprySOCKS, and the BIOPASS RAT.
A backdoor RAT variant used by Patchwork and SideWinder, supporting data collection and remote access.
Downloader referenced as previously used by 'Maha Grass'; mentioned due to similarities with StreamSpy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.