Prophet Spider
Also reported as GOLD MELODY and UNC961.
Reports per quarter
CVEs named in reports
- CVE-2016-0545
- CVE-2017-7504
- CVE-2018-0171 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-22205 KEV ransomware
Show all 39 CVEs Show fewer
- CVE-2021-22941 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-3120710
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-345239
- CVE-2021-40539 KEV ransomware
- CVE-2021-440077
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2022-1388 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-30190 KEV ransomware
- CVE-2025-29824 KEV ransomware
- CVE-2025-32433 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Egregor (Malware Family)
-
UNC961 in the Multiverse of Mandiant- Three Encounters with a Financially Motivated Threat Actor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor UNC961 in the Multiverse of Mandiant- Three Encounters with a Financially Motivated Threat Actor
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PROPHET SPIDER Exploits Citrix ShareFile Remote Code Execution Vulnerability CVE-2021-22941 to Deliver Webshell
-
Decryptable PartyTicket Ransomware Reportedly Targeting Ukrainian Entities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Decryptable PartyTicket Ransomware Reportedly Targeting Ukrainian Entities
-
CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks
Show all 16 reports Show fewer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2022GTR
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Log4U, Shell4Me
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2021ThreatHunting
-
PROPHET SPIDER Exploits Oracle WebLogic to Facilitate Ransomware Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PROPHET SPIDER Exploits Oracle WebLogic to Facilitate Ransomware Activity
Newest first. Details opens the report in Explore.