Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors DUNGEON SPIDER

Description

DUNGEON SPIDER is a criminal group operating the ransomware most commonly known as Locky, which has been active since February 2016 and was last observed in late 2017. Locky is a ransomware tool that encrypts files using a combination of cryptographic algorithms: RSA with a key size of 2,048 bits, and AES with a key size of 128 bits. Locky targets a large number of file extensions and is able to encrypt data on shared network drives. In an attempt to further impact victims and prevent file recovery, Locky deletes all of the Shadow Volume Copies on the machine. DUNGEON SPIDER primarily relies on broad spam campaigns with malicious attachments for distribution. Locky is the community/industry name associated with this actor.

AI Analysis

· 1 week ago

Executive Summary

DUNGEON SPIDER is a cybercriminal group known for operating the Locky ransomware, which has been active since February 2016. The group primarily distributes Locky through broad spam campaigns using malicious attachments. Locky encryption employs RSA (2,048 bits) and AES (128 bits) algorithms and targets numerous file extensions, including data on shared network drives. The ransomware also deletes Shadow Volume Copies to prevent file recovery. DUNGEON SPIDER's activity has been observed until late 2017.

Goals & Targeting

DUNGEON SPIDER's primary goal appears to be financial gain through the deployment of Locky ransomware. The group targets a broad range of industries, with no specific sector appearing to be the sole focus, though organizations with significant shared network drive usage are particularly at risk. The targeting strategy relies on large-scale spam campaigns, suggesting an intent to maximize victim numbers rather than focusing on high-value niche targets. This approach underscores DUNGEON SPIDER's operational adaptability and capacity for disrupting victims across multiple sectors.

Enhanced Description

DUNGEON SPIDER is a sophisticated cybercriminal group known for its involvement in the Locky ransomware campaign, first identified in February 2016 and last observed active in late 2017. The group's primary activity involves distributing Locky through large-scale spam campaigns using malicious attachments as the main delivery vector. Locky is a highly destructive ransomware that encrypts files using a combination of cryptographic algorithms: RSA with a key size of 2,048 bits and AES with a key size of 128 bits. The ransomware targets a wide range of file extensions, making it particularly damaging to organizations relying on shared network drives. To further prevent recovery, Locky deletes all Shadow Volume Copies on the infected machine, a tactic designed to maximize victim impact and reduce recovery options. DUNGEON SPIDER's operations demonstrate a focus on maximizing disruption and financial gain through the deployment of advanced ransomware capabilities.

Key Capabilities

  • Ransomware distribution via malicious email attachments
  • Advanced encryption using RSA/AES algorithms
  • Targeting shared network drives to maximize file destruction
  • Deletion of Shadow Volume Copies to prevent data recovery
  • Sophisticated spam campaign infrastructure

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Collection

ATT&CK Techniques

T1059.003
T1566.001
T1040
T1566.002

Software / Tooling

Locky Ransomware

Campaigns & Victims

DUNGEON SPIDER's campaigns are characterized by their broad reach and reliance on spam distribution. The group operates with significant volume, targeting numerous victims across various industries. Notable patterns include the use of malicious Office documents as delivery vectors and a focus on encrypting network-attached storage solutions. Despite their activity being last observed in late 2017, DUNGEON SPIDER's operational model may persist through affiliate programs or infrastructure reuse by other actors.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • Large-scale email campaigns delivering Locky ransomware
  • Encryption of numerous file types and network drives
  • Deletion of Shadow Volume Copies post-infection

Recommended Actions

  • Implement advanced email filtering to detect and block phishing messages
  • Regularly back up data and store copies offline or in secure cloud storage
  • Deploy endpoint detection and response (EDR) solutions to monitor for suspicious activities
  • Educate employees about phishing attempts and document attachments from unknown senders
  • Segment network drives and implement access controls to mitigate lateral movement

Suggested Tags

Ransomware
Criminal
Locky
Financial Gain
Spam Campaign

Confidence Assessment

The data available on DUNGEON SPIDER is limited, with most information focused on the Locky ransomware rather than the group's specific identity or long-term operations. The linking of specific MITRE techniques and tools remains speculative based on common ransomware tactics. There is a lack of precise TTPs attributed directly to DUNGEON SPIDER, but the group's activity demonstrates a clear understanding of encryption and data destruction techniques.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Phishing
Criminal
Locky
Financial Gain
Spam Campaign

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.