MUMMY SPIDER
Also reported as TA542, GOLD CRESTWOOD, Mummy Spider, ATK 104, Mealybug and 1 other name.
Reports per quarter
CVEs named in reports
- CVE-2012-5469
- CVE-2014-0160 KEV
- CVE-2014-0346
- CVE-2015-2051 KEV
- CVE-2016-5195 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-11292 KEV
- CVE-2017-11882 KEV ransomware
Show all 72 CVEs Show fewer
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-8291 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10561 KEV
- CVE-2018-13374 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-1181
- CVE-2019-13720 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2019-6703
- CVE-2019-9489
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-10826
- CVE-2020-10827
- CVE-2020-12061
- CVE-2020-13756
- CVE-2020-1472 KEV ransomware
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21974
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-22941 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-30116 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-41379 KEV ransomware
- CVE-2021-42321 KEV ransomware
- CVE-2021-43936
- CVE-2021-44228 KEV ransomware
- CVE-2022-24086 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-2868 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2025-68613 KEV
- CVE-2026-1731 KEV ransomware
- CVE-2026-20127 KEV
- CVE-2027-11882
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Mummy Spider, TA542 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Mummy Spider, TA542 - Threat Group Cards: A Threat Actor Encyclopedia
-
Indrik Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Indrik Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor IcedID (Malware Family)
-
Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
-
Bamboo Spider, TA544 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Bamboo Spider, TA544 - Threat Group Cards: A Threat Actor Encyclopedia
Show all 319 reports Show fewer
-
Doppel Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Doppel Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
Fork in the Ice- The New Era of IcedID
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fork in the Ice- The New Era of IcedID
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
A Comprehensive Look at Emotet Virus’ Fall 2022 Return
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Comprehensive Look at Emotet Virus’ Fall 2022 Return
-
VMware Brochure Template US Letter
The original link failed its last check. Original publisher Detailsfor VMware Brochure Template US Letter
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Emotet Summary- November 2021 Through January 2022
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emotet Summary- November 2021 Through January 2022
-
Detecting a MUMMY SPIDER campaign and Emotet infection
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting a MUMMY SPIDER campaign and Emotet infection
-
Detecting a MUMMY SPIDER campaign and Emotet infection
The original link failed its last check. Original publisher Detailsfor Detecting a MUMMY SPIDER campaign and Emotet infection
-
Emotet Tests New Delivery Techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emotet Tests New Delivery Techniques
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
The Ransomware Threat Landscape: What to Expect in 2022
The original link failed its last check. Original publisher Detailsfor The Ransomware Threat Landscape: What to Expect in 2022
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Headliners- Qakbot
-
Emotet 2.0: Everything you need to know about the new Variant of the Banking Trojan - CloudSEK
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Emotet 2.0: Everything you need to know about the new Variant of the Banking Trojan - CloudSEK
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mummy Spider’s Emotet Malware is Back After a Year Hiatus; Wizard Spider’s TrickBot Observed in Its Return
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2021-CTI-009
-
Análisis campaña Emotet - Security Art Work
The original link failed its last check. Original publisher Detailsfor Análisis campaña Emotet - Security Art Work
-
The original link failed its last check. Original publisher Detailsfor Botnet-update-Q1-2021.pdf
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
Q4 2020 Threat Report- A Quarterly Analysis of Cybersecurity Trends, Tactics and Themes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Q4 2020 Threat Report- A Quarterly Analysis of Cybersecurity Trends, Tactics and Themes
-
Emotet malware hits Lithuania's National Public Health Center
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emotet malware hits Lithuania's National Public Health Center
-
Using similarity to expand context and map out threat campaigns
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Using similarity to expand context and map out threat campaigns
-
Quick Post: Spooky New PowerShell Obfuscation in Emotet Maldocs
The original link failed its last check. Original publisher Detailsfor Quick Post: Spooky New PowerShell Obfuscation in Emotet Maldocs
-
Quick Post- Spooky New PowerShell Obfuscation in Emotet Maldocs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Quick Post- Spooky New PowerShell Obfuscation in Emotet Maldocs
-
The original link failed its last check. Original publisher Detailsfor The Many Faces of Emotet
-
WIZARD SPIDER Update- Resilient, Reactive and Resolute
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WIZARD SPIDER Update- Resilient, Reactive and Resolute
-
Emotet Makes Timely Adoption of Political and Elections Lures
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emotet Makes Timely Adoption of Political and Elections Lures
-
What's behind the increase in ransomware attacks this year?
The original link failed its last check. Original publisher Detailsfor What's behind the increase in ransomware attacks this year?
-
Case Study- Emotet Thread Hijacking, an Email Attack Technique
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Case Study- Emotet Thread Hijacking, an Email Attack Technique
-
Bulletin d'alerte du CERT-FR- Recrudescence d’activité Emotet en France
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Bulletin d'alerte du CERT-FR- Recrudescence d’activité Emotet en France
-
A Comprehensive Look at Emotet’s Summer 2020 Return
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor A Comprehensive Look at Emotet’s Summer 2020 Return
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-008
-
vmwcb-report-modern-bank-heists-2020.pdf
The original link failed its last check. Original publisher Detailsfor vmwcb-report-modern-bank-heists-2020.pdf
-
GuLoader delivers RATs and Spies in Disguise
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GuLoader delivers RATs and Spies in Disguise
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
The original link failed its last check. Original publisher Detailsfor TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
-
TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
-
Coronavirus Threat Landscape Update
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Coronavirus Threat Landscape Update
-
APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT36 jumps on the coronavirus bandwagon, delivers Crimson RAT _ Malwarebytes Labs
-
The original link failed its last check. Original publisher Detailsfor Dissecting Emotet - Part 2
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
Meet the white-hat group fighting Emotet, the world's most dangerous malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet the white-hat group fighting Emotet, the world's most dangerous malware
-
2020_State-of-Malware-Report.pdf
The original link failed its last check. Original publisher Detailsfor 2020_State-of-Malware-Report.pdf
-
The original link failed its last check. Original publisher Detailsfor Dissecting Emotet – Part 1
-
The original link failed its last check. Original publisher Detailsfor Forensics Report True Hedge
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor News Archiv
-
URLZone top malware in Japan, while Emotet and LINE Phishing round out the landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor URLZone top malware in Japan, while Emotet and LINE Phishing round out the landscape
-
Threat Actor Profile- TA542, From Banker to Malware Distribution Service
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Actor Profile- TA542, From Banker to Malware Distribution Service
-
Emotet Adds New Evasion Technique
The original link failed its last check. Original publisher Detailsfor Emotet Adds New Evasion Technique
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
Big Game Hunting with Ryuk- Another Lucrative Targeted Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting with Ryuk- Another Lucrative Targeted Ransomware
-
Digging into BokBot’s Core Module
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Digging into BokBot’s Core Module
-
URSNIF, EMOTET, DRIDEX and BitPayme Linked by Loader
The original link failed its last check. Original publisher Detailsfor URSNIF, EMOTET, DRIDEX and BitPayme Linked by Loader
-
Examining Emotet’s Activities, Infrastructure
The original link failed its last check. Original publisher Detailsfor Examining Emotet’s Activities, Infrastructure
-
The Evolution of Emotet- From Banking Trojan to Threat Distributor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Evolution of Emotet- From Banking Trojan to Threat Distributor
-
Meet CrowdStrike’s Adversary of the Month for February- MUMMY SPIDER
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Meet CrowdStrike’s Adversary of the Month for February- MUMMY SPIDER
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Holiday lull- Not so much
-
New EMOTET Hijacks a Windows API, Evades Sandbox
The original link failed its last check. Original publisher Detailsfor New EMOTET Hijacks a Windows API, Evades Sandbox
-
EMOTET Returns, Starts Spreading via Spam Botnet
The original link failed its last check. Original publisher Detailsfor EMOTET Returns, Starts Spreading via Spam Botnet
Newest first. Details opens the report in Explore.