Aviator Spider is a financially motivated cybercriminal threat actor assessed to originate from Nigeria. The group has been identified as shifting attention toward Latin America in 2024, indicating an expansion of its operational focus beyond previously observed activity. Available high-confidence reporting directly supports its classification as a criminal actor rather than a state-sponsored intrusion set. Specific victim sectors, tradecraft, malware families, and intrusion methods are not established in the supplied facts. Known alias: aviator_spider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.