Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Lunar Spider

Also known as: GOLD SWATHMORE

Description

**Targets:** Financial Crime **Toolset/Malware:** IcedID (BokBot) **Notes:** Cooperation with Wizard Spider

Goals & Targeting

Targeted Sectors

Financial services

AI Analysis

· 1 week ago

Executive Summary

Lunar Spider (also known as GOLD SWATHMORE) is a financially motivated nation-state actor targeting financial services sectors. The group employs sophisticated malware like IcedID (BokBot) and collaborates with Wizard Spider, indicating ties to broader cybercriminal networks. Their operations focus on financial crime, suggesting strategic efforts to exploit vulnerabilities in banking systems for monetary gain.

Goals & Targeting

Lunar Spider's strategic objectives revolve around financial gain through the exploitation of vulnerabilities in financial institutions. By targeting the financial services sector, the actor can access sensitive data, compromise transaction systems, or facilitate unauthorized transfers, which can yield substantial monetary benefits. The choice of financial institutions as targets also positions the actor to destabilize critical economic infrastructure, potentially exacerbating geopolitical tensions. The group's focus on financial crime suggests a direct alignment with cybercriminal objectives, even within a nation-state framework, indicating a hybrid model where strategic and financial motives intersect.

Enhanced Description

Lunar Spider is a nation-state threat actor with a primary focus on financial crime. The group leverages the IcedID (BokBot) malware family, which is known for its ability to steal banking credentials and facilitate financial fraud. Collaboration with Wizard Spider suggests potential access to a wider array of tools and infrastructure, enhancing the actor's capacity to conduct large-scale attacks. Their operations are characterized by a high degree of coordination and technical sophistication, enabling them to bypass traditional security defenses. The group's activities are believed to be driven by financial motives, with a clear emphasis on targeting institutions within the financial services sector. Although specific campaigns are not detailed in the provided data, their association with known cybercriminal networks implies a potential for sustained and adaptive threat campaigns.

Key Capabilities

  • Deployment of IcedID (BokBot) malware for financial theft and credential extraction
  • Collaboration with Wizard Spider for access to advanced cybercriminal infrastructure
  • Execution of spear-phishing campaigns targeting financial institutions
  • Use of malicious Office documents with embedded macros for initial compromise
  • Establishment of command-and-control (C2) infrastructure for persistent access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Exfiltration

ATT&CK Techniques

T1560.001 - Phishing - Spearphishing Attachment
T1204.002 - User Execution - Malicious File
T1059.003 - Command and Scripting Interpreter - PowerShell
T1038 - Access Token Manipulation
T1566 - Phishing - Spearphishing Link

Software / Tooling

IcedID (BokBot)
Wizard Spider toolset (likely including Emotet, TrickBot)

Campaigns & Victims

Lunar Spider's campaigns are likely characterized by a fast operational tempo, leveraging known malware families and collaborative networks to execute attacks against financial institutions. The actor's use of IcedID (BokBot) suggests a focus on credential theft and financial fraud rather than espionage or sabotage. Given the group's ties to Wizard Spider, there may be joint operations involving multi-stage attacks, lateral movement within networks, and the use of modular malware for extended persistence. Notable past operations may involve targeting banks and payment processors through phishing and malware distribution.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 communication over HTTP/HTTPS using compromised domains
  • Staging infrastructure on bulletproof hosting services
  • Presence of IcedID payloads in network traffic
  • Use of malicious scripts for credential harvesting

Recommended Actions

  • Implement advanced email filtering and user training to detect spear-phishing attempts
  • Deploy endpoint detection and response (EDR) solutions to identify IcedID activity
  • Monitor network traffic for suspicious C2 patterns using domain-based indicators
  • Regularly update and patch systems to mitigate exploitation of known vulnerabilities
  • Conduct red-team exercises to simulate attacks and validate defensive measures

Suggested Tags

APT
financial-gain
banking-trojan
nation-state
finance-sector

Confidence Assessment

The confidence level is moderate, as the available data confirms the group's toolset (IcedID) and association with Wizard Spider, but information gaps exist regarding specific MITRE techniques, campaign timelines, and full operational details. The actor's motives and targeting behavior are inferred based on known financial malware patterns and collaborations, though additional intelligence would strengthen the analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
financial-gain
banking-trojan
nation-state
finance-sector

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Financial gain
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.