Spyder is a modular Windows backdoor used in PRC-linked cyberespionage operations for long-term monitoring of compromised systems. It is associated with APT41 and FishMonger, the latter also tracked as Earth Lusca and TAG-22 and overlapping with RedHotel activity. FishMonger has deployed Spyder alongside ShadowPad as a primary backdoor for sustained espionage. Documented deployments include intrusions against Hong Kong universities and a Thai government organization during Operation FishMedley in 2022.
Spyder has been deployed through a dedicated loader downloaded from a compromised internal web server. Observed samples communicate with command-and-control infrastructure over TLS, and some infrastructure overlaps with servers identified as ShadowPad command-and-control endpoints. Spyder contains command-handling code that processes the same command data structure as Winnti 4.0 Worker, although this overlap does not establish that the two are the same malware family. Spyder forms part of an espionage toolkit that also includes Cobalt Strike, FunnySwitch, BIOPASS RAT, and SprySOCKS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
They are now using it and another backdoor called Spyder as their primary backdoors for long-term monitoring.
Spyder and ReverseWindow are APT malware utilized by PRC-linked cyber espionage threat actors (respectively APT41 and LuoYu).
"We also found some similarities between this Trojan and the Spyder downloader used by Maha Grass."
7 distinct techniques documented for this family, organized by ATT&CK tactic.
For years, I have reversed the C2 protocols of high-profile APT malware families then, by emulating the protocols, discovered the active C2 servers on the Internet... both pieces of malware support multiple C2 protocols, such as TCP / TLS / HTTP / HTTPS / UDP.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of FishMonger’s toolkit.
FishMonger’s toolset includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, SprySOCKS, and the BIOPASS RAT.
A backdoor RAT variant used by Patchwork and SideWinder, supporting data collection and remote access.
Downloader referenced as previously used by 'Maha Grass'; mentioned due to similarities with StreamSpy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.