Skip to main content
Mallory
MalwareUsed by 3 actors

Spyder

Spyder is a custom modular backdoor associated primarily with the China-aligned FishMonger intrusion set, which is also tracked under the Winnti umbrella and overlaps with reporting on RedHotel/TAG-22. It has been described as a backdoor typically used by FishMonger and as part of RedHotel’s bespoke malware families alongside FunnySwitch, while also appearing in earlier Winnti-linked activity targeting Hong Kong universities. ESET reported Spyder use during Operation FishMedley in 2022 against organizations in Taiwan, Thailand, Hungary, Turkey, the United States, and France, including government entities, NGOs, a think tank, and Catholic organizations. In one observed intrusion at a Thai government victim, a Spyder loader was downloaded from a compromised internal web server as aa.doc and dropped as C:\Users\Public\task.exe. The Spyder payload used the hardcoded C2 server 61.238.103[.]165; multiple subdomains of junlper[.]com resolved to that IP in 2022, and junlper[.]com was identified as a known Spyder C2 domain designed as a homoglyph of juniper.net. A self-signed TLS certificate with thumbprint 89EDCFFC66EDA3AEB75E140816702F9AC73A75F0 was observed on port 443 of 61.238.103[.]165 from May to December 2022 and was previously associated with FishMonger. Additional reporting links Spyder to RedHotel, a prolific Chinese state-sponsored threat group active since at least 2019 that targeted government, academia, aerospace, media, telecommunications, and R&D sectors across at least 17 countries from 2021 to 2023. Separate content also notes similarity-based links between StreamSpy and Spyder, and describes Spyder as a variant of a backdoor named WarHawk attributed to SideWinder, but the strongest direct attribution in the provided material is to FishMonger/RedHotel.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Fishmonger

FishMonger’s toolset includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, SprySOCKS, and the BIOPASS RAT.

via eset welivesecurity blogwelivesecurity.com
APT41

...but also the Spyder backdoor...

via eset welivesecurity blogwelivesecurity.com
Maha Grass

"We also found some similarities between this Trojan and the Spyder downloader used by Maha Grass."

via ctoatncsc substackctoatncsc.substack.com
MITRE ATT&CK

Techniques & procedures

5 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

2 techniques
T1583.001DomainsEvidence1

FishMonger bought domains and used them for C&C traffic.

T1583.004ServerEvidence1

FishMonger rented servers at several hosting providers.

Execution

2 techniques
T1059.003Windows Command ShellEvidence1

FishMonger deployed Spyder using a BAT script.

T1072Software Deployment ToolsEvidence1

At Victim D, the attackers gained access to an admin console and used it to deploy implants on other machines in the local network.

Stealth

1 technique
T1140Deobfuscate/Decode Files or InformationEvidence1

ShadowPad, Spyder, and SodaMaster are decrypted and loaded into memory.

Lateral Movement

1 technique
T1072Software Deployment ToolsEvidence1

At Victim D, the attackers gained access to an admin console and used it to deploy implants on other machines in the local network.

INDICATORS OF COMPROMISE

IOCs tracked for this family

5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
2 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app3 months ago
domain●●●●●●●●●●●●View more in app1 year ago
hash.sha1●●●●●●●●●●●●View more in app1 year ago
uri●●●●●●●●●●●●View more in app3 years ago
uri●●●●●●●●●●●●View more in app3 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching5

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution3

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping5

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.