Mallard Spider is the threat actor associated with development and operation of QakBot, a long-running eCrime malware platform widely used to enable follow-on intrusions. QakBot infections have been observed preceding hands-on-keyboard activity, Cobalt Strike deployment, lateral movement, data theft, and eventual ransomware deployment by downstream operators. Mallard Spider has also been assessed as likely acting as an access broker for big game hunting ransomware operators, providing initial footholds that other criminal actors monetize. The actor’s activity is best characterized as financially motivated cybercrime centered on initial compromise and post-compromise enablement. Reported intrusion chains involving QakBot include malware delivery followed by interactive post-exploitation, credential access, movement across victim environments, and exfiltration in support of later-stage extortion or ransomware operations conducted by partners or customers. Mallard Spider is distinct from Lunar Spider, which has been associated with IcedID, but both malware ecosystems have been cited as common precursors to major ransomware intrusions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.