Also known as: GOLD LAGOON
Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER
Executive Summary
MALLARD SPIDER, also known as GOLD LAGOON, is a sophisticated threat actor associated with the Qbot malware family. This group primarily targets financial institutions through phishing campaigns and malware deployments, aiming to steal sensitive data and disrupt operations. Their activities demonstrate advanced persistent threat (APT) capabilities.
Goals & Targeting
MALLARD SPIDER's primary objectives appear to be the compromise of financial institutions, likely for financial gain and intelligence gathering. They exhibit a preference for targeting sectors with high economic value, such as banking and finance, and show no apparent geographic limitations in their operations. Their victims are typically selected based on industry sector rather than specific geographies.
Enhanced Description
MALLARD SPIDER is tracked by CrowdStrike as operating behind the Qbot malware, which is closely related to the TrickBot banking Trojan. This group has a history of targeting financial services globally, leveraging sophisticated tactics such as spear-phishing, payload deployment via malicious .dll files, and credential theft. Their operations often involve multi-stage campaigns to establish long-term persistence in targeted networks, exfiltrating sensitive data for espionage or financial gain.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
MALLARD SPIDER has been involved in numerous campaigns targeting financial institutions, often using Qbot as the primary payload. Their operations demonstrate a focus on long-term access to compromised networks, with indicators of espionage activity. Notable past operations include compromises affecting North American and European financial entities, leveraging TrickBot's capabilities for large-scale banking fraud.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in the threat actor's identity and TTPs, based on known associations with Qbot/TRickBot malware. Further details regarding specific campaigns or unique operational methods would enhance confidence levels.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics