LUNAR SPIDER
Also reported as GOLD SWATHMORE, Lunar Spider and Gold SwathMore. Linked to Russia by one source.
Reports per quarter
CVEs named in reports
- CVE-2003-1138
- CVE-2005-1380
- CVE-2010-0817
- CVE-2010-3936
- CVE-2011-1264
- CVE-2012-0507 KEV ransomware
- CVE-2013-0074 KEV ransomware
- CVE-2013-2551 KEV ransomware
- CVE-2014-3567
- CVE-2014-6271 KEV
- CVE-2014-6277
- CVE-2014-6278 KEV
Show all 74 CVEs Show fewer
- CVE-2014-6332 KEV
- CVE-2015-0313 KEV
- CVE-2015-2419 KEV
- CVE-2016-0189 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2017-0068
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-14100
- CVE-2017-15399
- CVE-2017-5638 KEV ransomware
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-13374 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-6882 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0752 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1225
- CVE-2019-13720 KEV
- CVE-2019-1579 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-22986 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-3120710
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-345239
- CVE-2021-40444 KEV ransomware
- CVE-2021-42278 KEV ransomware
- CVE-2021-42287 KEV ransomware
- CVE-2021-44228 KEV ransomware
- CVE-2022-30190 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BlackCat (Malware Family)
-
Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
Show all 180 reports Show fewer
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
ITG23 crypters cooperation between cybercriminal groups
The original link failed its last check. Original publisher Detailsfor ITG23 crypters cooperation between cybercriminal groups
-
Shelob Moonlight – Spinning a Larger Web From IcedID to CONTI, a Trojan and Ransomware collaboration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Shelob Moonlight – Spinning a Larger Web From IcedID to CONTI, a Trojan and Ransomware collaboration
-
Let’s set ice on fire: Hunting and detecting IcedID infections
The original link failed its last check. Original publisher Detailsfor Let’s set ice on fire: Hunting and detecting IcedID infections
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IcedID Analysis
-
The original link failed its last check. Original publisher Detailsfor Binary Defense
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
IcedID Stealer Man-in-the-browser Banking Trojan
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor IcedID Stealer Man-in-the-browser Banking Trojan
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of Valak Maldoc
-
The original link failed its last check. Original publisher Detailsfor Analysis of Valak Maldoc
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
IcedID PNG -> PE parser and reconstructor for custom steganographic loader
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID PNG -> PE parser and reconstructor for custom steganographic loader
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Interception- Dissecting BokBot’s “Man in the Browser”
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Interception- Dissecting BokBot’s “Man in the Browser”
-
New Evidence Proves Ongoing WIZARD SPIDER - LUNAR SPIDER Collaboration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Evidence Proves Ongoing WIZARD SPIDER - LUNAR SPIDER Collaboration
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
“Sin”-ful SPIDERS- WIZARD SPIDER and LUNAR SPIDER Sharing the Same Web
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor “Sin”-ful SPIDERS- WIZARD SPIDER and LUNAR SPIDER Sharing the Same Web
-
Digging into BokBot’s Core Module
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Digging into BokBot’s Core Module
Newest first. Details opens the report in Explore.