sp1d3r is a cybercriminal threat actor publicly associated with the sale of large datasets allegedly stolen from organizations compromised through Snowflake customer environments in 2024. The actor has been linked to the monetization of data taken from Advance Auto Parts and has been discussed alongside other actors involved in the broader wave of Snowflake-related intrusions. In the reported activity, access to victim environments was assessed to have relied on stolen credentials, with successful compromise facilitated where multi-factor authentication was not enabled. Investigative reporting and vendor assessments tied the broader intrusion pattern to credential harvesting by information-stealing malware rather than exploitation of a Snowflake product vulnerability. The actor’s observed tradecraft in this reporting is centered on post-compromise data theft and criminal resale of exfiltrated information. The advertised datasets included large volumes of customer, transaction, loyalty-program, and employment-related records, indicating a focus on extracting high-value personal and commercial data for direct financial gain. The known activity supports assessment of capabilities in initial access through use of stolen credentials, exfiltration, and post-exploitation actions related to staging and selling stolen data. The available information does not directly support ransomware deployment or encryption activity by this actor in the cited incidents.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Sp1d3r is a threat actor involved in selling large volumes of stolen data from cloud storage breaches, specifically targeting Snowflake customers such as Advance Auto Parts.
Claimed responsibility for selling 3TB of data stolen from Advance Auto Parts after breaching the company's Snowflake account, as part of broader attacks targeting Snowflake customers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.