Blind Spider
Blind Spider is a financially motivated threat actor identified by CrowdStrike as one of six major operators targeting Latin America, alongside Ocular Spider, Odyssey Spider, Plump Spider, Samba Spider, and Squab Spider. CrowdStrike states these operators are either based in Latin America or primarily focused on targets in the region. The provided content also notes Blind Spider is also known as Blind Eagle. Separately, Sophos assessed that malware campaigns involving the HeartCrypt packer-as-a-service were not attributable to Blind Spider alone: although HeartCrypt activity had some geographic overlap with cases CrowdStrike tracks as Blind Spider, Sophos found sufficient differences in payloads, injection mechanisms, and targeted locations to conclude multiple threat actors were using HeartCrypt rather than a single actor such as Blind Spider. The content further states that Blind Spider has been cited among threat actors that have leveraged AI in their operations. No additional high-confidence targeting, tooling, or TTP details specific to Blind Spider are directly provided in the source content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇨🇴 Colombia
Tradecraft
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as leveraging AI in operations (no additional operational details provided in the content).
Financially motivated criminal activity cluster identified as a major operator in Latin America; described as based in LATAM or primarily focused on targets in the region.
Referenced as a possible but ultimately unconfirmed affiliate or user of the HeartCrypt packer-as-a-service operation, with geographic overlap in targeting, particularly Colombia.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.