TRAVELING SPIDER, also known as Nemty, is a financially motivated ransomware-as-a-service operation. Its affiliates have conducted intrusions by exploiting or accessing internet-exposed FortiGate VPN appliances, then used Remote Desktop Protocol and Windows Remote Management for lateral movement and remote execution. Observed post-compromise activity includes PowerShell-based Active Directory and network-share reconnaissance, network scanning, manipulation of account group membership including Domain Admins, and changes to file ownership, permissions, and RDP authentication settings. Affiliates have exfiltrated business data using Rclone before deploying INC ransomware against Windows systems and VMware ESXi hypervisors. The group has also used healthcare-organization impersonation in pandemic-themed malicious campaigns. Nemty has been associated with the broader ransomware ecosystem through use of IcedID for initial access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware activity leveraging COVID-19-themed lures; impersonates healthcare organizations as part of pandemic-related campaigns.
Ransomware group referenced as affiliated with Lunar Spider and leveraging IcedID for initial access.
A ransomware-as-a-service operation whose affiliate conducted at least five intrusions from February to April 2026. The affiliate accessed internet-exposed FortiGate VPN appliances, moved laterally through RDP and WinRM, performed Active Directory and network-share reconnaissance, exfiltrated data with Rclone to Wasabi S3 buckets, and deployed INC ransomware against VMware ESXi and Windows systems.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.