Crowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authentication to gain access to victim organizations through Citrix Gateway and send extortion-related emails using the victim’s own Microsoft Office 365 instance.
Executive Summary
TRAVELING SPIDER is a cyber threat actor known for developing the Nemty ransomware. They exploit single-factor authentication (SFA) in Citrix Gateway to gain network access, using compromised Microsoft Office 365 accounts to send extortion emails, leveraging psychological manipulation to coerce victims into paying ransoms.
Goals & Targeting
TRAVELING SPIDER's primary goal appears to be financial gain through ransomware distribution and psychological coercion. They target sectors with weaker cybersecurity measures, such as healthcare and education, where SFA is more common and incident response may not be as robust. Their focus on global campaigns suggests an intent to maximize geographic reach, potentially exploiting regions or industries with less sophisticated security defenses. Victims are typically organizations that rely on Citrix Gateway with SFA and have a presence in Microsoft Office 365, making them easier targets for initial penetration.
Enhanced Description
TRAVELING SPIDER operates by compromising victim organizations through weak security practices, exploiting single-factor authentication (SFA) mechanisms on Citrix Gateway. Once inside the network, they escalate privileges and deploy the Nemty ransomware to encrypt sensitive data. The actor then uses the victim's own Microsoft Office 365 infrastructure to send malicious emails, blending in with legitimate communication channels to extort payment from affected organizations. This tactic not only increases the psychological pressure on victims but also complicates incident detection. TRAVELING SPIDER primarily targets sectors where SFA is prevalent and cybersecurity measures are relatively weaker, such as healthcare, education, and small businesses. Their global footprint suggests an interest in maximizing their attack surface by targeting regions with varying security postures, potentially focusing on areas with less mature incident response capabilities. The use of extortion emails further indicates a strategy to prolong the impact of their ransomware campaigns, ensuring victims face both data loss and reputational damage.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TRAVELING SPIDER has been active since at least 2019, with campaigns targeting multiple countries and sectors. Their use of extortion emails in addition to ransomware ensures prolonged impact on victims. Notable campaigns involve compromising victims' email accounts post-infiltration to send malicious messages, thereby creating a cycle of fear and urgency that often leads to payment. Past operations suggest a preference for regions where SFA is prevalent and incident response capabilities are less mature.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in TRAVELING SPIDER's attributed actions is moderate, primarily based on the analysis by CrowdStrike regarding their association with Nemty. Some details about TTPs and exact targeting criteria remain unclear or speculative, particularly around tools beyond Nemty and specific campaign patterns beyond SFA exploitation. Additional data on their attack chains and tools would improve confidence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics