SCULLY SPIDER
Also reported as TA547 and Scully Spider.
Reports per quarter
Techniques seen in the last two years
- T1001.001 1 report
- T1005 1 report
- T1008 1 report
- T1010 1 report
- T1020 1 report
- T1021.001 1 report
- T1021.005 1 report
- T1027.007 1 report
- T1030 1 report
- T1041 1 report
Show all 45 techniques Show fewer
- T1055.001 1 report
- T1056.001 1 report
- T1057 1 report
- T1083 1 report
- T1090.003 1 report
- T1095 1 report
- T1106 1 report
- T1113 1 report
- T1115 1 report
- T1119 1 report
- T1125 1 report
- T1132.001 1 report
- T1185 1 report
- T1204.001 1 report
- T1204.002 1 report
- T1217 1 report
- T1218.007 1 report
- T1218.010 1 report
- T1218.011 1 report
- T1219 1 report
- T1498 1 report
- T1539 1 report
- T1548.002 1 report
- T1555.003 1 report
- T1560.002 1 report
- T1560.003 1 report
- T1566.001 1 report
- T1571 1 report
- T1573.001 1 report
- T1573.002 1 report
- T1583.003 1 report
- T1583.004 1 report
- T1583.008 1 report
- T1587.001 1 report
- T1608.001 1 report
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-7248
- CVE-2015-7254
- CVE-2017-0199 KEV ransomware
- CVE-2017-11882 KEV ransomware
Show all 37 CVEs Show fewer
- CVE-2017-9805 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-8611 KEV
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-11899 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-2021 KEV ransomware
- CVE-2020-7961 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-41379 KEV ransomware
- CVE-2021-44228 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
Pinchy Spider, Gold Southfield - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Pinchy Spider, Gold Southfield - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
-
Scully Spider, TA547 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Scully Spider, TA547 - Threat Group Cards: A Threat Actor Encyclopedia
Show all 68 reports Show fewer
-
Russian State-Sponsored and Criminal Cyber .pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian State-Sponsored and Criminal Cyber .pdf
-
Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA22-110A)- Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure
-
The original link failed its last check. Original publisher Detailsfor Decoding a DanaBot Downloader
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
Cobalt Strike- Favorite Tool from APT to Crimeware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cobalt Strike- Favorite Tool from APT to Crimeware
-
The First Step- Initial Access Leads to Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The First Step- Initial Access Leads to Ransomware
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
TA547 Pivots from Ursnif Banking Trojan to Ransomware in Australian Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA547 Pivots from Ursnif Banking Trojan to Ransomware in Australian Campaign
-
CTNT_Q1_2020_COVID-Report_Final.pdf
The original link failed its last check. Original publisher Detailsfor CTNT_Q1_2020_COVID-Report_Final.pdf
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
Danabot's Travels, A Global Perspective | NETSCOUT
The original link failed its last check. Original publisher Detailsfor Danabot's Travels, A Global Perspective | NETSCOUT
-
DanaBot - A new banking Trojan surfaces Down Under
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DanaBot - A new banking Trojan surfaces Down Under
Newest first. Details opens the report in Explore.