Hook Spider is an eCrime initial access broker active on Russian-language underground forums including Exploit, RAMP, and XSS. The actor has been assessed as a supplier of network access to multiple big-game-hunting ransomware adversaries, placing it within the broader cybercriminal access marketplace that supports ransomware and data-theft operations. Available reporting directly supports Hook Spider’s role as an access seller aligned with ransomware ecosystems, but does not provide high-confidence detail on specific malware families, victimology, operational geography, or a broader alias set beyond the Hook Spider name. Based on the supported facts, Hook Spider is best characterized as a financially motivated cybercriminal actor specializing in initial access brokerage for downstream extortion and ransomware operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.