Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TRAVELING SPIDER

Description

Crowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authentication to gain access to victim organizations through Citrix Gateway and send extortion-related emails using the victim’s own Microsoft Office 365 instance.

AI Analysis

· 1 week ago

Executive Summary

TRAVELING SPIDER is a cyber threat actor known for developing the Nemty ransomware. They exploit single-factor authentication (SFA) in Citrix Gateway to gain network access, using compromised Microsoft Office 365 accounts to send extortion emails, leveraging psychological manipulation to coerce victims into paying ransoms.

Goals & Targeting

TRAVELING SPIDER's primary goal appears to be financial gain through ransomware distribution and psychological coercion. They target sectors with weaker cybersecurity measures, such as healthcare and education, where SFA is more common and incident response may not be as robust. Their focus on global campaigns suggests an intent to maximize geographic reach, potentially exploiting regions or industries with less sophisticated security defenses. Victims are typically organizations that rely on Citrix Gateway with SFA and have a presence in Microsoft Office 365, making them easier targets for initial penetration.

Enhanced Description

TRAVELING SPIDER operates by compromising victim organizations through weak security practices, exploiting single-factor authentication (SFA) mechanisms on Citrix Gateway. Once inside the network, they escalate privileges and deploy the Nemty ransomware to encrypt sensitive data. The actor then uses the victim's own Microsoft Office 365 infrastructure to send malicious emails, blending in with legitimate communication channels to extort payment from affected organizations. This tactic not only increases the psychological pressure on victims but also complicates incident detection. TRAVELING SPIDER primarily targets sectors where SFA is prevalent and cybersecurity measures are relatively weaker, such as healthcare, education, and small businesses. Their global footprint suggests an interest in maximizing their attack surface by targeting regions with varying security postures, potentially focusing on areas with less mature incident response capabilities. The use of extortion emails further indicates a strategy to prolong the impact of their ransomware campaigns, ensuring victims face both data loss and reputational damage.

Key Capabilities

  • Ransomware deployment using Nemty
  • Social engineering via email communications
  • Persistence through compromised Office 365 accounts
  • Exploitation of Citrix Gateway single-factor authentication (SFA)
  • Experienced in global campaign operations

MITRE ATT&CK Tactics

Initial Access
Credential Access

ATT&CK Techniques

T1566.003 - Compromise Account via Credential Breach (Single-Factor Authentication)
T1078 - OS Credential Dumping (Persistence with Extortion Email Campaign)

Software / Tooling

Nemty Ransomware

Campaigns & Victims

TRAVELING SPIDER has been active since at least 2019, with campaigns targeting multiple countries and sectors. Their use of extortion emails in addition to ransomware ensures prolonged impact on victims. Notable campaigns involve compromising victims' email accounts post-infiltration to send malicious messages, thereby creating a cycle of fear and urgency that often leads to payment. Past operations suggest a preference for regions where SFA is prevalent and incident response capabilities are less mature.

IOC Patterns

  • Exploitation of single-factor authentication on Citrix Gateway
  • Compromise of Microsoft Office 365 accounts sending malicious emails
  • Deployment of Nemty ransomware files in encrypted directories

Recommended Actions

  • Implement multi-factor authentication (MFA) for Citrix Gateway and other critical systems.
  • MonitorMicrosoft Office 365 logs for unauthorized email sends or account compromises.
  • Patch Citrix Gateway to eliminate SFA vulnerabilities.
  • Conduct regular audits of Single Sign-On (SSO) integrations with Azure AD.
  • Enhance incident response plans to address ransomware and internal communication breaches.

Suggested Tags

Ransomware
Extortion Email
Enduring Presence
Global Operations
Weak Security Postures

Confidence Assessment

The confidence in TRAVELING SPIDER's attributed actions is moderate, primarily based on the analysis by CrowdStrike regarding their association with Nemty. Some details about TTPs and exact targeting criteria remain unclear or speculative, particularly around tools beyond Nemty and specific campaign patterns beyond SFA exploitation. Additional data on their attack chains and tools would improve confidence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Extortion Email
Enduring Presence
Global Operations
Weak Security Postures

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.