Mentioned as operator of DanaBot in CrowdStrike's 2020 Report.
Executive Summary
SCULLY SPIDER is a threat actor identified as the operator of DanaBot, a sophisticated banking Trojan highlighted in CrowdStrike's 2020 report. This group primarily targets financial institutions and sectors, leveraging their malware for large-scale financial fraud and data exfiltration.
Goals & Targeting
SCULLY SPIDER's strategic objectives are centered on financial gain through banking fraud. They target the financial sector, including retail banking, corporate finance, and payment services. The actor's global targeting suggests a focus on broadening their victim base to increase potential earnings. Their campaigns typically aim to infiltrate organizations with weaker security measures, exploiting human vulnerabilities and technological gaps for maximum impact.
Enhanced Description
SCULLY SPIDER operates the DanaBot恶意软件, which is designed to steal banking credentials and facilitate fraudulent activities. The actor is known for targeting financial services globally, compromising both corporate and individual accounts. Their operations demonstrate a high level of technical proficiency, utilizing advanced persistence mechanisms and command-and-control (C2) infrastructure. SCULLY SPIDER's activities align with financially motivated cybercriminal groups who seek to maximize profit through large-scale campaigns against vulnerable sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SCULLY SPIDER has been active since at least 2020, with a notable focus on targeted campaigns against financial institutions. Their operational tempo suggests periodic attacks, often exploiting seasonal opportunities or vulnerabilities in financial systems. Past operations include large-scale phishing campaigns and the deployment of DanaBot to infiltrate banking networks.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is high in SCULLY SPIDER's association with DanaBot and their targeting of the financial sector. However, specific details about their TTPs and exact campaigns remain limited to public reporting in CrowdStrike's analysis. Additional intelligence on their full capabilities and geographic focus would further enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics