Odyssey Spider is a financially motivated cybercriminal threat actor identified as one of the major operators targeting Latin America. The group is also tracked as TA558. Reporting places it among a set of prominent financially motivated actors that are either based in Latin America or primarily focused on victims in the region. Odyssey Spider has been specifically cited as an adversary that has leveraged artificial intelligence in its operations. Beyond that, the available high-confidence information does not provide a detailed public characterization of its malware families, intrusion chain, or preferred initial access methods. Its inclusion among leading regional e-crime operators indicates a criminal operational focus consistent with credential-centric and intrusion-driven activity affecting organizations in Latin America, but specific tactics, techniques, victim sectors, and country-by-country targeting are not directly established here. Known alias: TA558.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as leveraging AI in operations (no additional operational details provided in the content).
Financially motivated criminal activity cluster identified as a major operator in Latin America; described as based in LATAM or primarily focused on targets in the region.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.