Samba Spider is a financially motivated cybercriminal threat actor identified as one of the major operators targeting Latin America. The group is associated with the regional cybercrime ecosystem rather than state-sponsored activity. Reporting places Samba Spider among a set of prominent financially motivated operators active in or focused on Latin America, alongside Ocular Spider, Blind Spider, Odyssey Spider, Plump Spider, and Squab Spider. High-confidence public information directly attributes Samba Spider to financially motivated operations targeting organizations in Latin America, but does not provide detailed, corroborated tradecraft specific to this actor beyond its inclusion in that operator set. Available reporting does not establish confirmed sub-groups, malware families, or a more granular victimology for Samba Spider alone. Within the broader regional context, financially motivated intrusion activity in Latin America has been associated with ransomware, identity-based intrusions, and access-broker activity, but those behaviors are not specifically and individually attributed to Samba Spider at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.