DUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and was last observed in late 2017. Locky is a ransomware tool that encrypts files using a combination of cryptographic algorithms: RSA with a key size of 2,048 bits, and AES with a key size of 128 bits. Locky targets a large number of file extensions and is able to encrypt data on shared network drives. In an attempt to further impact victims and prevent file recovery, Locky deletes all of the Shadow Volume Copies on the machine. DUNGEON SPIDER primarily relies on broad spam campaigns with malicious attachments for distribution. Locky is the community/industry name associated with this actor.
Executive Summary
DUNGEON SPIDER is a cybercriminal group known for operating the Locky ransomware, which has been active since February 2016. The group primarily distributes Locky through broad spam campaigns using malicious attachments. Locky encryption employs RSA (2,048 bits) and AES (128 bits) algorithms and targets numerous file extensions, including data on shared network drives. The ransomware also deletes Shadow Volume Copies to prevent file recovery. DUNGEON SPIDER's activity has been observed until late 2017.
Goals & Targeting
DUNGEON SPIDER's primary goal appears to be financial gain through the deployment of Locky ransomware. The group targets a broad range of industries, with no specific sector appearing to be the sole focus, though organizations with significant shared network drive usage are particularly at risk. The targeting strategy relies on large-scale spam campaigns, suggesting an intent to maximize victim numbers rather than focusing on high-value niche targets. This approach underscores DUNGEON SPIDER's operational adaptability and capacity for disrupting victims across multiple sectors.
Enhanced Description
DUNGEON SPIDER is a sophisticated cybercriminal group known for its involvement in the Locky ransomware campaign, first identified in February 2016 and last observed active in late 2017. The group's primary activity involves distributing Locky through large-scale spam campaigns using malicious attachments as the main delivery vector. Locky is a highly destructive ransomware that encrypts files using a combination of cryptographic algorithms: RSA with a key size of 2,048 bits and AES with a key size of 128 bits. The ransomware targets a wide range of file extensions, making it particularly damaging to organizations relying on shared network drives. To further prevent recovery, Locky deletes all Shadow Volume Copies on the infected machine, a tactic designed to maximize victim impact and reduce recovery options. DUNGEON SPIDER's operations demonstrate a focus on maximizing disruption and financial gain through the deployment of advanced ransomware capabilities.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DUNGEON SPIDER's campaigns are characterized by their broad reach and reliance on spam distribution. The group operates with significant volume, targeting numerous victims across various industries. Notable patterns include the use of malicious Office documents as delivery vectors and a focus on encrypting network-attached storage solutions. Despite their activity being last observed in late 2017, DUNGEON SPIDER's operational model may persist through affiliate programs or infrastructure reuse by other actors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data available on DUNGEON SPIDER is limited, with most information focused on the Locky ransomware rather than the group's specific identity or long-term operations. The linking of specific MITRE techniques and tools remains speculative based on common ransomware tactics. There is a lack of precise TTPs attributed directly to DUNGEON SPIDER, but the group's activity demonstrates a clear understanding of encryption and data destruction techniques.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics