Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SAMBASPIDER

Also known as: other aliases, 0mid16B, APT28, several other aliases, ALPHV, Gleaming Pisces, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, BokBot, Gold Southfield, PlayCrypt, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, Turbine Panda, Hippo Team, JerseyMikes

Description

SAMBASPIDER is a highly versatile threat actor associated with the Mispadu malware family and reported in leaked 100,000‑line IOC lists generated by a US Department of Defense analysis of CrowdStrike data. The actor operates primarily through supply‑chain compromises—most notably strategic web compromise (SWC)—in which third‑party hosting providers are subverted to infiltrate victim websites. This approach gives the group stealthy persistence and wide exposure across government, critical infrastructure, financial services, healthcare, telecommunications, defense, and more. Technically, SAMBASPIDER uses a Java-based backdoor, Backdoor.JAVA.SAMBASPY.THIBOBD, that delivers payloads ranging from credential harvesters to fileless PowerShell implants. It also frequently supplements these tactics with spear‑phishing attachments or links, watering‑hole drops, Android spyware exploitation, and custom downloader components (e.g., Latrodectus, Lotus loader). The actor’s command & control traffic is often routed through commercial satellite networks such as Starlink, providing a highly resilient communication channel. In addition to initial compromise, the group has been observed deploying double‑extortion ransomware schemes that exfiltrate data before encrypting it. While precise attribution remains complex due to alias overlap with Turla, MuddyWater, and other state‑sponsored units, documented activity patterns align closely with nation‑state objectives: destabilizing economies, compromising critical infrastructure, and extracting financial gain. Overall, SAMBASPIDER demonstrates a sophisticated blend of classic credential‑theft tactics with advanced persistence mechanisms and emerging satellite‑based C2 techniques, placing it among the most resilient operators in contemporary threat landscapes.

TTP Summary

Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Critical infrastructure
Education
Manufacturing
Media
Non profit
Energy
Aviation
Hospitality
Aerospace
Pharmaceutical
Think tank
Retail
Gaming
Transportation
Information technology
Legal services
Mining
Chemical
Maritime
Utilities
Nuclear
Entertainment
Oil gas
Construction
Aerospace & defense
Legal

Targeted Countries / Regions

CN
US
RU
IR
IL
VN
IN
AU
SA
JP
UA
KP
BR
GB
KR
PK
TW
AE
MX
SG
DE
TR
BY
NG
ES
PL
CA
RO
FR
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

SAMBASPIDER, also known as Samba Spider, is a sophisticated threat actor linked to Mispadu malware and various state-sponsored groups such as Turla and MuddyWater. The group employs spear‑phishing, watering holes, Java-based backdoors, and commercial satellite (Starlink) C2 channels to target a wide spectrum of sectors across dozens of countries, frequently utilizing double‑extortion ransomware tactics. Recent leaks from a USDoD CrowdStrike IOC dump have shed new light on its supply‑chain attack methods and operational reach.

Goals & Targeting

SAMBASPIDER’s strategic objectives appear to be dual‑faced: first, to secure financial profit through ransom and double‑extortion campaigns; second, to disrupt adversary state interests by infiltrating high‑value targets across an extensive set of industries—including defense, energy, government, and finance—spanning a broad geographic spread. The group prioritizes access and persistence in politically sensitive sectors and frequently leverages supply‑chain vectors and satellite C2 to evade detection and maintain long‑lived footholds.

Enhanced Description

Key Capabilities

  • Spearphishing campaigns for initial access
  • Watering hole attacks via compromised websites
  • Java-based backdoor delivery (Backdoor.JAVA.SAMBASPY.THIBOBD)
  • Custom downloader components (Latrodectus, Lotus loader)
  • Credential harvesting and dumping
  • Fileless PowerShell implants
  • Android spyware exploitation
  • Command & control via commercial satellite internet (Starlink)
  • Double‑extortion ransomware with data exfiltration before encryption

MITRE ATT&CK Tactics

Initial Access
Execution
Command and Control
Exfiltration
Data Encrypted for Impact
Credential Acquisition
Persistence

ATT&CK Techniques

T1566.001
T1566.002
T1189
T1041
T1486
T1003
T1086

Software / Tooling

Backdoor.JAVA.SAMBASPY.THIBOBD
IcedID (BokBot)
Latency Ratel downloader
Lotus loader
Brute Ratel
Cobalt Strike
PowerShell

Campaigns & Victims

SAMBASPIDER’s operations follow a pattern of low‑profiling initial compromise via social engineering or supply‑chain attacks, followed by the deployment of long‑term Java backdoors and advanced credential‑stealing modules. The group has been active at least since the early 2010s and continues to evolve its tactics, evidenced by recent satellite‑based C2 usage and double‑extortion ransomware campaigns. Victims range from state agencies in the US and Europe to commercial enterprises worldwide, with a notable focus on sectors that provide critical infrastructure or strategic advantage.

IOC Patterns

  • Java-based backdoor indicators
  • Starlink satellite C2 traffic patterns
  • Credential harvesting artifacts
  • Spear-phishing email attachments/links
  • Fileless PowerShell execution logs
  • Android spyware implant signatures

Recommended Actions

  • Implement targeted phishing awareness training focused on spear‑phish detection
  • Deploy advanced email filtering and attachment sandboxing to block malicious files and links
  • Monitor and restrict PowerShell usage with endpoint detection policies
  • Detect fileless malware by monitoring for unusual process creation patterns
  • Enforce device security controls and threat hunting on Android endpoints
  • Harden web hosting environments against watering-hole attacks
  • Segment networks to isolate critical systems from potential supply‑chain breaches
  • Conduct regular patching of known vulnerabilities in third‑party services
  • Implement outbound traffic monitoring to flag satellite C2 usage

Suggested Tags

SAMBASPIDER
APT28
Turla
MuddyWater
State-sponsored
Nation-state
Double-Extortion Ransomware
Commercial Satellite C2
Spear-Phishing
Fileless-Malware
PowerShell-Backdoor
Android-Spyware
Government-Targeting

Confidence Assessment

Confidence in the core behaviors of SAMBASPIDER—including the use of a Java backdoor, spear‑phishing, watering holes, satellite C2, and double‑extortion ransomware—relies on multiple independent intelligence sources, including leaked IOC datasets and threat reports. However, attribution to a single nation or organization remains ambiguous due to alias overlap with Turla, MuddyWater, and other state actors. Gaps include precise operational timelines, confirmed geographical origin, and the full extent of supply‑chain infrastructure used. Therefore, while evidence for tactics and techniques is solid, strategic attribution should be treated as moderate confidence pending further corroboration.

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 3 SHA-256 Hash 2 Domain 13 IPv4 Address 1 MD5 Hash 1

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. attack.mitre.org — Cited by web research for: Custom malware
  3. www.crowdstrike.com — Cited by web research for: STOP
  4. unit42.paloaltonetworks.com — Cited by web research for: test.txt
  5. https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/backdoor.java.sambaspy.thibobd — Cited by AI analysis.
  6. https://www.crowdstrike.com/en-us/adversaries/samba-spider/ — Cited by AI analysis.

Intel Summary

7

Techniques

73

Tools

7

Campaigns

39

IOCs

0

Observed Data

5

Tactics

Tags

state-sponsored
cyber-espionage
military-targeting
IOC-leakage
SAMBASPIDER
APT28
Turla
MuddyWater
State-sponsored
Nation-state
Double-Extortion Ransomware
Commercial Satellite C2
Spear-Phishing
Fileless-Malware
PowerShell-Backdoor
Android-Spyware
Government-Targeting

Details

MITRE ID
APT26
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.