Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors MALLARD SPIDER

Also known as: GOLD LAGOON

Description

Crowdstrike tarcks the operators behind the Qbot as MALLARD SPIDER

AI Analysis

· 1 week ago

Executive Summary

MALLARD SPIDER, also known as GOLD LAGOON, is a sophisticated threat actor associated with the Qbot malware family. This group primarily targets financial institutions through phishing campaigns and malware deployments, aiming to steal sensitive data and disrupt operations. Their activities demonstrate advanced persistent threat (APT) capabilities.

Goals & Targeting

MALLARD SPIDER's primary objectives appear to be the compromise of financial institutions, likely for financial gain and intelligence gathering. They exhibit a preference for targeting sectors with high economic value, such as banking and finance, and show no apparent geographic limitations in their operations. Their victims are typically selected based on industry sector rather than specific geographies.

Enhanced Description

MALLARD SPIDER is tracked by CrowdStrike as operating behind the Qbot malware, which is closely related to the TrickBot banking Trojan. This group has a history of targeting financial services globally, leveraging sophisticated tactics such as spear-phishing, payload deployment via malicious .dll files, and credential theft. Their operations often involve multi-stage campaigns to establish long-term persistence in targeted networks, exfiltrating sensitive data for espionage or financial gain.

Key Capabilities

  • Advanced persistent threat (APT) capabilities
  • Use of Qbot/TRickBot malware for banking Trojan activities
  • Spear-phishing campaigns utilizing malicious emails and URLs
  • Payload deployment via .dll files dropped from initial infection vectors
  • Credential theft through mimicked Windows processes
  • Persistence mechanisms including registry entries and WMI persistence
  • Lateral movement using PSCommand and other tools

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Lateral Movement

ATT&CK Techniques

T1566.001
T1059.003
T1548.002
T1055
T1546.004

Software / Tooling

Qbot/TRickBot
rundll32.exe
Microsoft PSCommand
kill.exe
netsh.exe
Windows utilities for persistence and lateral movement

Campaigns & Victims

MALLARD SPIDER has been involved in numerous campaigns targeting financial institutions, often using Qbot as the primary payload. Their operations demonstrate a focus on long-term access to compromised networks, with indicators of espionage activity. Notable past operations include compromises affecting North American and European financial entities, leveraging TrickBot's capabilities for large-scale banking fraud.

IOC Patterns

  • Spear-phishing emails containing malicious URLs or macro-laced documents
  • File dropped from initial infection: *.exe or *.dll related to Qbot/TRickBot family
  • Registry entries associated with known persistence mechanisms (e.g., Run key modifications)
  • Network traffic to and from command-and-control (C2) servers via HTTP/HTTPS protocols

Recommended Actions

  • Implement multi-layered email filtering to detect phishing attempts
  • Monitor for suspicious activity in banking applications and network endpoints
  • Deploy endpoint detection and response (EDR) solutions to identify and block known malicious processes
  • Conduct regular user training on phishing awareness
  • Enforce strong password policies and multi-factor authentication where possible
  • Monitor for indicators of compromise related to Qbot/TRickBot activity

Suggested Tags

APT Group
Banking Trojan
Financial Sector Targeting
Spear-Phishing
Malware

Confidence Assessment

Moderate confidence in the threat actor's identity and TTPs, based on known associations with Qbot/TRickBot malware. Further details regarding specific campaigns or unique operational methods would enhance confidence levels.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
APT Group
Banking Trojan
Financial Sector Targeting
Spear-Phishing
Malware

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.