Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Zombie Spider

Also known as: Pytor Levashov, Kelihos

Description

**Notes:** Criminal

AI Analysis

· 1 week ago

Executive Summary

Zombie Spider, also known as Pytor Levashov or Kelihos, is a nation-state threat actor primarily motivated by espionage. This actor has targeted various sectors and countries to gather sensitive information. While specific details about their targeting profiles and capabilities are limited in the provided data, established intelligence links suggest they employ sophisticated tactics commonly associated with advanced persistent threats.

Goals & Targeting

Zombie Spider targets sectors and countries where intelligence collection would yield strategic advantages for their nation-state sponsor. Their targeting strategy likely focuses on industries or regions where sensitive political, military, or economic information is concentrated. The actor's persistence and use of sophisticated techniques indicate that they are highly disciplined and well-resourced, aiming to achieve long-term goals through sustained operations.

Enhanced Description

Zombie Spider is a significant player in the cyber threat landscape, known for their nation-state activities and espionage-focused operations. Their primary objective appears to be the collection of sensitive information from targeted entities, which could include government agencies, private sector organizations, or critical infrastructure. This actor has demonstrated persistence over time, indicating a long-term commitment to achieving their objectives. The aliases 'Kelihos' and 'Pytor Levashov' further suggest a historical and potentially ongoing campaign pattern, consistent with the behavior of state-sponsored actors.

Key Capabilities

  • Spear-phishing
  • Email-based attacks
  • Custom malware development
  • Lateral movement

Software / Tooling

Kelihos Botnet
Custom恶意软件
Phishing tools

Campaigns & Victims

Zombie Spider has been linked to long-term campaigns targeting high-value assets. Their operations often involve persistent access and data exfiltration over extended periods, indicating a focus on stealth and endurance rather than rapid impact. The actor's historical use of the Kelihos botnet suggests a preference for large-scale infrastructure compromise, which could facilitate espionage or intelligence gathering.

Recommended Actions

  • Implement multi-layered email security to detect phishing attempts
  • Monitor network traffic for signs of persistent threats
  • Conduct regular threat-hunting exercises focusing on nation-state TTPs

Suggested Tags

APT
espionage
cyber-espionage
nation-state

Confidence Assessment

The confidence level in the data is moderate. While there are established links to known campaigns and methodologies, specific details about Zombie Spider's recent activity, exact targeting patterns, and full capabilities remain unclear. Additional intelligence on their current TTPs and tools would significantly enhance this assessment.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
espionage
cyber-espionage
nation-state

Details

Type
Nation-State
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
70%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.