Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RATPAK SPIDER

Description

In July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked. This malware has been linked to the targeting of Russia’s financial sector. Associated malware, Buhtrap, which has been leaked previously, was observed this year in connection with SWC campaigns that also targeted Russian users.

AI Analysis

· 1 week ago

Executive Summary

RATPAK SPIDER is a cyber threat actor known for targeting Russia's financial sector since at least July 2018, when their malware framework's source code was leaked. Their activities include sophisticated campaigns using malware such as Pegasus and Buhtrap, which are linked to credential theft and SWIft-based fraud. The group demonstrates moderate sophistication, focusing on high-value targets in the financial industry.

Goals & Targeting

RATPAK SPIDER's strategic objectives appear centered around targeting financial institutions in Russia, possibly to steal sensitive data or disrupt operations. Their choice of victims reflects an interest in sectors with high concentrations of valuable assets, where successful attacks could yield significant financial gains. The actor's targeting profile suggests a focus on opportunities within the financial ecosystem, potentially aligning with broader cybercrime trends in Eastern Europe.

Enhanced Description

RATPAK SPIDER emerged in prominence following the July 2018 leak of their malware framework's source code, revealing a sophisticated operation targeting Russia's financial sector. This actor is associated with malicious activities including data theft, credential harvesting, and SWIft-based fraudulent transactions, as evidenced by connections to the Buhtrap malware. Observations tie RATPAK SPIDER to campaigns that overlap with known APT groups like TA505 and other financially motivated threat actors, suggesting a focus on monetizable targets through cyberespionage and fraud.

Key Capabilities

  • Custom malware development (Pegasus framework)
  • Sophisticated SWIft-based fraudulent transactions
  • Credential theft and lateral movement using Buhtrap
  • Targeted attacks against financial institutions

MITRE ATT&CK Tactics

Credential Access
Lateral Movement
Discovery
Exfiltration
Data Theft

ATT&CK Techniques

T1096.001 - OS Credential Dumping: Windows Credentials via LSASS Memory
T1538.001 - Pass the Ticket: Kerberos Tickets
T1270 - Lateral Movement via Remote Server

Software / Tooling

Pegasus (malware framework)
Buhtrap (malware)

Campaigns & Victims

RATPAK SPIDER's campaigns have targeted Russian financial institutions, leveraging sophisticated malware to compromise systems and steal data. Their operations suggest a focus on financially motivated cybercrime, with potential ties to broader APT activity in the region. Notable patterns include the use of leaked toolkits and modular malware frameworks, indicating reuse of existing capabilities.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments targeting financial sector employees
  • C2 communication via encrypted channels or legitimate services
  • SWIft transaction manipulation indicators
  • Presence of Pegasus or Buhtrap malware on compromised systems

Recommended Actions

  • Monitor SWIft and banking-related traffic for anomalies
  • Enhance user training to recognize phishing attempts
  • Implement robust endpoint detection and response (EDR) solutions
  • Conduct regular security audits of financial systems
  • Apply patches to mitigate known vulnerabilities in financial software

Suggested Tags

Financial-sector APT
Banking Trojan
SWIft Fraud
Russian Cybercrime

Confidence Assessment

Confidence in RATPAK SPIDER's details is moderate, as while their existence and some TTPs are confirmed through malware leaks and observed activity, specific campaign details remain limited. The group likely operates with a moderate level of sophistication but exact origins and full capabilities remain unclear.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
Hacktivism
Financial-sector APT
Banking Trojan
SWIft Fraud
Russian Cybercrime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.