Also known as: GOLD SWATHMORE
**Targets:** Financial Crime **Toolset/Malware:** IcedID (BokBot) **Notes:** Cooperation with Wizard Spider
Targeted Sectors
Executive Summary
Lunar Spider (also known as GOLD SWATHMORE) is a financially motivated nation-state actor targeting financial services sectors. The group employs sophisticated malware like IcedID (BokBot) and collaborates with Wizard Spider, indicating ties to broader cybercriminal networks. Their operations focus on financial crime, suggesting strategic efforts to exploit vulnerabilities in banking systems for monetary gain.
Goals & Targeting
Lunar Spider's strategic objectives revolve around financial gain through the exploitation of vulnerabilities in financial institutions. By targeting the financial services sector, the actor can access sensitive data, compromise transaction systems, or facilitate unauthorized transfers, which can yield substantial monetary benefits. The choice of financial institutions as targets also positions the actor to destabilize critical economic infrastructure, potentially exacerbating geopolitical tensions. The group's focus on financial crime suggests a direct alignment with cybercriminal objectives, even within a nation-state framework, indicating a hybrid model where strategic and financial motives intersect.
Enhanced Description
Lunar Spider is a nation-state threat actor with a primary focus on financial crime. The group leverages the IcedID (BokBot) malware family, which is known for its ability to steal banking credentials and facilitate financial fraud. Collaboration with Wizard Spider suggests potential access to a wider array of tools and infrastructure, enhancing the actor's capacity to conduct large-scale attacks. Their operations are characterized by a high degree of coordination and technical sophistication, enabling them to bypass traditional security defenses. The group's activities are believed to be driven by financial motives, with a clear emphasis on targeting institutions within the financial services sector. Although specific campaigns are not detailed in the provided data, their association with known cybercriminal networks implies a potential for sustained and adaptive threat campaigns.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Lunar Spider's campaigns are likely characterized by a fast operational tempo, leveraging known malware families and collaborative networks to execute attacks against financial institutions. The actor's use of IcedID (BokBot) suggests a focus on credential theft and financial fraud rather than espionage or sabotage. Given the group's ties to Wizard Spider, there may be joint operations involving multi-stage attacks, lateral movement within networks, and the use of modular malware for extended persistence. Notable past operations may involve targeting banks and payment processors through phishing and malware distribution.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level is moderate, as the available data confirms the group's toolset (IcedID) and association with Wizard Spider, but information gaps exist regarding specific MITRE techniques, campaign timelines, and full operational details. The actor's motives and targeting behavior are inferred based on known financial malware patterns and collaborations, though additional intelligence would strengthen the analysis.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics