In July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked. This malware has been linked to the targeting of Russia’s financial sector. Associated malware, Buhtrap, which has been leaked previously, was observed this year in connection with SWC campaigns that also targeted Russian users.
Executive Summary
RATPAK SPIDER is a cyber threat actor known for targeting Russia's financial sector since at least July 2018, when their malware framework's source code was leaked. Their activities include sophisticated campaigns using malware such as Pegasus and Buhtrap, which are linked to credential theft and SWIft-based fraud. The group demonstrates moderate sophistication, focusing on high-value targets in the financial industry.
Goals & Targeting
RATPAK SPIDER's strategic objectives appear centered around targeting financial institutions in Russia, possibly to steal sensitive data or disrupt operations. Their choice of victims reflects an interest in sectors with high concentrations of valuable assets, where successful attacks could yield significant financial gains. The actor's targeting profile suggests a focus on opportunities within the financial ecosystem, potentially aligning with broader cybercrime trends in Eastern Europe.
Enhanced Description
RATPAK SPIDER emerged in prominence following the July 2018 leak of their malware framework's source code, revealing a sophisticated operation targeting Russia's financial sector. This actor is associated with malicious activities including data theft, credential harvesting, and SWIft-based fraudulent transactions, as evidenced by connections to the Buhtrap malware. Observations tie RATPAK SPIDER to campaigns that overlap with known APT groups like TA505 and other financially motivated threat actors, suggesting a focus on monetizable targets through cyberespionage and fraud.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
RATPAK SPIDER's campaigns have targeted Russian financial institutions, leveraging sophisticated malware to compromise systems and steal data. Their operations suggest a focus on financially motivated cybercrime, with potential ties to broader APT activity in the region. Notable patterns include the use of leaked toolkits and modular malware frameworks, indicating reuse of existing capabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in RATPAK SPIDER's details is moderate, as while their existence and some TTPs are confirmed through malware leaks and observed activity, specific campaign details remain limited. The group likely operates with a moderate level of sophistication but exact origins and full capabilities remain unclear.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics