MALLARD SPIDER
Also reported as GOLD LAGOON, Mallard Spider and Gold Lagoon.
Reports per quarter
Techniques seen in the last two years
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2017-0199 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-2021 KEV ransomware
- CVE-2021-21974
- CVE-2022-27924 KEV ransomware
- CVE-2022-30190 KEV ransomware
Show all 19 CVEs Show fewer
- CVE-2023-23397 KEV
- CVE-2023-3519 KEV ransomware
- CVE-2024-27564
- CVE-2024-30051 KEV ransomware
- CVE-2024-4577 KEV ransomware
- CVE-2025-24813 KEV
- CVE-2025-49704 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor QakBot (Malware Family)
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2021-CTI-009
-
Detecting Cobalt Strike- Cybercrime Attacks (GOLD LAGOON)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting Cobalt Strike- Cybercrime Attacks (GOLD LAGOON)
Show all 11 reports Show fewer
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
Newest first. Details opens the report in Explore.