Also known as: other aliases, 0mid16B, APT28, several other aliases, ALPHV, Gleaming Pisces, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, BokBot, Gold Southfield, PlayCrypt, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, Turbine Panda, Hippo Team, JerseyMikes
SAMBASPIDER is a highly versatile threat actor associated with the Mispadu malware family and reported in leaked 100,000‑line IOC lists generated by a US Department of Defense analysis of CrowdStrike data. The actor operates primarily through supply‑chain compromises—most notably strategic web compromise (SWC)—in which third‑party hosting providers are subverted to infiltrate victim websites. This approach gives the group stealthy persistence and wide exposure across government, critical infrastructure, financial services, healthcare, telecommunications, defense, and more. Technically, SAMBASPIDER uses a Java-based backdoor, Backdoor.JAVA.SAMBASPY.THIBOBD, that delivers payloads ranging from credential harvesters to fileless PowerShell implants. It also frequently supplements these tactics with spear‑phishing attachments or links, watering‑hole drops, Android spyware exploitation, and custom downloader components (e.g., Latrodectus, Lotus loader). The actor’s command & control traffic is often routed through commercial satellite networks such as Starlink, providing a highly resilient communication channel. In addition to initial compromise, the group has been observed deploying double‑extortion ransomware schemes that exfiltrate data before encrypting it. While precise attribution remains complex due to alias overlap with Turla, MuddyWater, and other state‑sponsored units, documented activity patterns align closely with nation‑state objectives: destabilizing economies, compromising critical infrastructure, and extracting financial gain. Overall, SAMBASPIDER demonstrates a sophisticated blend of classic credential‑theft tactics with advanced persistence mechanisms and emerging satellite‑based C2 techniques, placing it among the most resilient operators in contemporary threat landscapes.
Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites
Targeted Sectors
Targeted Countries / Regions
Executive Summary
SAMBASPIDER, also known as Samba Spider, is a sophisticated threat actor linked to Mispadu malware and various state-sponsored groups such as Turla and MuddyWater. The group employs spear‑phishing, watering holes, Java-based backdoors, and commercial satellite (Starlink) C2 channels to target a wide spectrum of sectors across dozens of countries, frequently utilizing double‑extortion ransomware tactics. Recent leaks from a USDoD CrowdStrike IOC dump have shed new light on its supply‑chain attack methods and operational reach.
Goals & Targeting
SAMBASPIDER’s strategic objectives appear to be dual‑faced: first, to secure financial profit through ransom and double‑extortion campaigns; second, to disrupt adversary state interests by infiltrating high‑value targets across an extensive set of industries—including defense, energy, government, and finance—spanning a broad geographic spread. The group prioritizes access and persistence in politically sensitive sectors and frequently leverages supply‑chain vectors and satellite C2 to evade detection and maintain long‑lived footholds.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SAMBASPIDER’s operations follow a pattern of low‑profiling initial compromise via social engineering or supply‑chain attacks, followed by the deployment of long‑term Java backdoors and advanced credential‑stealing modules. The group has been active at least since the early 2010s and continues to evolve its tactics, evidenced by recent satellite‑based C2 usage and double‑extortion ransomware campaigns. Victims range from state agencies in the US and Europe to commercial enterprises worldwide, with a notable focus on sectors that provide critical infrastructure or strategic advantage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core behaviors of SAMBASPIDER—including the use of a Java backdoor, spear‑phishing, watering holes, satellite C2, and double‑extortion ransomware—relies on multiple independent intelligence sources, including leaked IOC datasets and threat reports. However, attribution to a single nation or organization remains ambiguous due to alias overlap with Turla, MuddyWater, and other state actors. Gaps include precise operational timelines, confirmed geographical origin, and the full extent of supply‑chain infrastructure used. Therefore, while evidence for tactics and techniques is solid, strategic attribution should be treated as moderate confidence pending further corroboration.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
7
Techniques
73
Tools
7
Campaigns
39
IOCs
0
Observed Data
5
Tactics