ANTHROPOID SPIDER is a CrowdStrike-tracked eCrime intrusion actor associated with opportunistic exploitation of vulnerable web servers to deliver MedusaLocker ransomware. Public reporting ties the actor’s 2020 activity to web server exploitation campaigns rather than long-term covert espionage, indicating a financially motivated intrusion set focused on initial compromise and ransomware deployment. The actor is known primarily by the ANTHROPOID SPIDER name; no additional high-confidence aliases are established in the supplied facts. Reported behavior supports capabilities in initial access through exploitation, post-compromise deployment activity, and ransomware operations involving encryption. High-confidence details beyond those points are limited in the supplied material.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.