Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SCULLY SPIDER

Description

Mentioned as operator of DanaBot in CrowdStrike's 2020 Report.

AI Analysis

· 1 week ago

Executive Summary

SCULLY SPIDER is a threat actor identified as the operator of DanaBot, a sophisticated banking Trojan highlighted in CrowdStrike's 2020 report. This group primarily targets financial institutions and sectors, leveraging their malware for large-scale financial fraud and data exfiltration.

Goals & Targeting

SCULLY SPIDER's strategic objectives are centered on financial gain through banking fraud. They target the financial sector, including retail banking, corporate finance, and payment services. The actor's global targeting suggests a focus on broadening their victim base to increase potential earnings. Their campaigns typically aim to infiltrate organizations with weaker security measures, exploiting human vulnerabilities and technological gaps for maximum impact.

Enhanced Description

SCULLY SPIDER operates the DanaBot恶意软件, which is designed to steal banking credentials and facilitate fraudulent activities. The actor is known for targeting financial services globally, compromising both corporate and individual accounts. Their operations demonstrate a high level of technical proficiency, utilizing advanced persistence mechanisms and command-and-control (C2) infrastructure. SCULLY SPIDER's activities align with financially motivated cybercriminal groups who seek to maximize profit through large-scale campaigns against vulnerable sectors.

Key Capabilities

  • sophisticated malware development (e.g., DanaBot)
  • banking Trojan functionality for credential theft
  • advanced persistence techniques
  • C2 infrastructure management
  • large-scale campaign orchestration

MITRE ATT&CK Tactics

Lateral Movement
Exfiltration
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

DanaBot
Phishing Emails with malicious attachments
Credential Dumping Tools
C2 Frameworks

Campaigns & Victims

SCULLY SPIDER has been active since at least 2020, with a notable focus on targeted campaigns against financial institutions. Their operational tempo suggests periodic attacks, often exploiting seasonal opportunities or vulnerabilities in financial systems. Past operations include large-scale phishing campaigns and the deployment of DanaBot to infiltrate banking networks.

IOC Patterns

  • Spear-phishing emails with attachments (e.g., .exe files)
  • Domain registrations mimicking legitimate financial institutions
  • C2 communication via HTTPS for persistence

Recommended Actions

  • Implement multi-layered phishing detection and prevention solutions.
  • Monitor for unusual activity in banking credentials systems.
  • Conduct regular employee training on financial fraud indicators.
  • Apply robust network monitoring to detect C2 activities.

Suggested Tags

APT
Banking Trojan
Financial Fraud
Cybercrime

Confidence Assessment

Confidence is high in SCULLY SPIDER's association with DanaBot and their targeting of the financial sector. However, specific details about their TTPs and exact campaigns remain limited to public reporting in CrowdStrike's analysis. Additional intelligence on their full capabilities and geographic focus would further enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
APT
Banking Trojan
Financial Fraud
Cybercrime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.