Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Mummy Spider

Also known as: TA542, GOLD CRESTWOOD

Description

**Toolset/Malware:** Emotet **Notes:** Criminal

AI Analysis

· 1 week ago

Executive Summary

Mummy Spider (TA542, GOLD CRESTWOOD), a nation-state threat actor with potential criminal affiliations, primarily engages in espionage activities targeting energy and government entities. Known for employing Emotet malware, this group seeks to compromise sensitive information through sophisticated campaigns. Their operations have been observed since 2017, focusing on sectors critical to national stability.

Goals & Targeting

Mummy Spider targets energy sector entities and government institutions to gather political and economic intelligence. This targeting suggests a focus on espionage for strategic advantage.

Enhanced Description

Mummy Spider is a nation-state actor with criminal links, operating primarily in the energy sector and targeting government institutions, particularly in Eastern Europe. Utilizing Emotet malware, this group has conducted long-term campaigns aimed at stealing sensitive data. Their activity spans from initial infections through phishing emails to credential dumping and lateral movement within targeted networks, showcasing their ability to maintain persistence.

Key Capabilities

  • Emotet malware
  • Spear-phishing via email attachments

MITRE ATT&CK Tactics

Credential Access
Collection

ATT&CK Techniques

T1566
T1046

Software / Tooling

Emotet

Campaigns & Victims

Mummy Spider uses campaigns requiring extended dwell time, leveraging Emotet for initial compromise and lateral movement. Their victims include energy companies and government bodies in Eastern Europe.

IOC Patterns

  • Phishing emails with Emotet attachments
  • Document macros activating Emotet

Recommended Actions

  • Implement email filters to detect phishing attempts
  • Monitor network processes

Suggested Tags

APT
espionage
energy-sector

Confidence Assessment

High confidence in their nation-state and criminal affiliations, though specific campaign details remain unclear.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
energy-sector

Details

MITRE ID
TA542
Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.