Also known as: GOLD MELODY, UNC961
PROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web servers, which commonly involves leveraging a variety of publicly disclosed vulnerabilities. The adversary has likely functioned as an access broker — handing off access to a third party to deploy ransomware — in multiple instances.
Executive Summary
Prophet Spider is an eCrime threat actor identified as GOLD MELODY or UNC961. Active since May 2017, Prophet Spider primarily compromises vulnerable web servers using publicly disclosed vulnerabilities and functions as an access broker for third-party ransomware deployments.
Goals & Targeting
Prophet Spider's strategic objectives appear to be centered around financial gain through cybercriminal activities. Their targeting profile focuses on sectors with vulnerable web servers, particularly those in the financial and retail industries, where such vulnerabilities are common. The group likely targets countries with less robust cybersecurity measures and organizations that lack comprehensive patch management practices. By acting as an intermediary for ransomware operators, Prophet Spider capitalizes on existing attack infrastructure to maximize their profit from each compromise.
Enhanced Description
Prophet Spider is a cybercriminal group that operates with a primary focus on exploiting vulnerable web servers to gain unauthorized access to networks. This threat actor has been observed since at least May 2017, leveraging known vulnerabilities in web server technologies, often involving publicly disclosed CVEs (Common Vulnerabilities and Exposures). Prophet Spider's activities suggest they operate as an access broker, providing initial entry points to target networks for third-party actors who deploy ransomware. This business model indicates a focus on financial gain through facilitating ransomware attacks rather than directly conducting malicious campaigns themselves.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Prophet Spider's campaign patterns involve targeting vulnerable web servers across various industries. Their operational tempo suggests they are active and adaptable, likely collaborating with other cybercriminal groups to maximize the impact of their access brokering activities. Notable past operations link Prophet Spider to several ransomware incidents in the financial sector, though specific details remain scarce due to lack of disclosure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in Prophet Spider's details is low due to limited available data. Key information gaps include exact motivations beyond financial gain, specific tools used for initial access, and detailed campaign timelines. The group's role as an access broker complicates attribution to specific attacks.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics