Renaissance Spider is a financially motivated eCrime threat actor based in the Russian Federation. The content states it was first observed in mid-2019, while another cited mention says it has been active since October 2017. It uses malspam campaigns and targeted intrusion operations, and has also used AI to translate ClickFix lures into Ukrainian. The group has conducted influence and sabotage activity using inauthentic hacktivist personas including "DaVinci Group" and "Fire Cells Group." Additional reporting in the content says Renaissance Spider coordinated physical attacks, kidnapping, arson, and fake bomb threats in Europe through Telegram-based networks, likely aiming to undermine support for Ukraine. The content also states that Russia's Renaissance Spider began shifting attention to Latin America in 2024. Known aliases and associated names directly mentioned in the content are Renaissance Spider, DaVinci Group, and Fire Cells Group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-based financially motivated cybercrime group using AI to localize/translate ClickFix social-engineering lures (e.g., fake CAPTCHA themes) to improve targeting effectiveness.
Russia-based financially motivated eCrime actor (mid-2019) using malspam and targeted intrusions; also conducts influence/sabotage via inauthentic hacktivist personas.
Renaissance Spider is a Russia-affiliated cybercriminal group involved in both digital and physical extortion, including ransomware, violence-as-a-service, and psychological operations such as fake bomb threats.
Financially motivated threat group described as Russia-linked that began shifting attention to Latin America in 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.