According to Crowdstrike, the NetWalker ransomware is being developed and maintained by a Russian-speaking actor designated as CIRCUS SPIDER. Initially discovered in September 2019and havinga compilation timestamp dating back to 28 August 2019, NetWalker has been found to be used in Big Game Hunting (BGH)-style operations while also being distributed via spam. CIRCUS SPIDER is advertising NetWalkeras being a closed-affiliate program,and verifies applicants before they are being accepted as an affiliate. The requirements rangefrom providing proof of previous revenue in similar affiliates programs, experience in the field and what type of industry the applicantis targeting.
Executive Summary
CIRCUS SPIDER is a Russian-speaking threat actor associated with the NetWalker ransomware. The group operates as an affiliate program, targeting high-value organizations in sectors like healthcare and education through phishing campaigns and Big Game Hunting (BGH) tactics. Their activities have been observed since September 2019, with ongoing operations primarily focused on financial gain through ransomware deployment.
Goals & Targeting
CIRCUS SPIDER's primary goal appears to be financial gain through ransomware operations. They focus on high-value targets in sectors such as healthcare, education, and local government, which are often attractive due to the critical nature of their services and potential for large financial payouts. The group's targeting strategy likely involves identifying organizations with weaker cybersecurity measures and limited resources to respond effectively to incidents. Their affiliate program model suggests an interest in maximizing reach and impact while maintaining a degree of operational separation from direct involvement in attacks.
Enhanced Description
CIRCUS SPIDER is a sophisticated Russian-speaking cybercriminal group known for maintaining and distributing the NetWalker ransomware. The group operates as an invite-only affiliate program, recruiting individuals or groups to participate in their malicious activities. Affiliates must meet specific criteria, including prior experience in similar programs, expertise in targeting particular industries, and proof of revenue generation. This model suggests a focus on high-value targets within sectors such as healthcare, education, and local governments, where the impact of ransomware can be significant both financially and reputationally. The group's operation leverages various attack vectors, including phishing emails containing malicious links or attachments, and exploit kits to gain initial access to victim networks. Once inside, NetWalker encrypts sensitive data and demands payment for decryption keys. CIRCUS SPIDER has demonstrated a preference for targeting organizations in English-speaking countries, possibly due to the higher perceived value of these targets. The group's ability to adapt their tactics over time indicates a certain level of operational maturity and resourcefulness.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CIRCUS SPIDER has been active since late 2019, with campaigns targeting various industries through both phishing and direct exploit attempts. Their use of an affiliate program indicates a focus on scalability and geographic diversity in their attacks. Notable campaigns have targeted healthcare facilities, educational institutions, and municipal organizations, resulting in significant disruptions. The group's operational tempo appears to be opportunistic, with increased activity during periods when targets are more vulnerable or less prepared.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
moderately confident based on available data. The group's operational model and toolset are well-documented, but specific details such as exact targeting criteria and long-term strategic goals remain unclear.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics