Zebra2104 is an intrusion cluster associated with Prophet Spider, an initial access broker known for compromising enterprise environments and monetizing that access, including by enabling follow-on ransomware operations. Observed activity links the group to exploitation of Log4Shell vulnerabilities in VMware Horizon, after which it commonly launches command shells or PowerShell from the Horizon service context to retrieve second-stage payloads. Post-exploitation activity has included deployment of cryptocurrency miners, occasional use of Cobalt Strike for broader hands-on-keyboard operations, and cleanup actions to remove artifacts after execution. The group’s tradecraft includes exploitation of internet-facing services for initial access, encoded PowerShell download cradles, use of scheduled tasks for persistence, host and domain reconnaissance, credential theft through registry hive dumping, and webshell-style modification of VMware Horizon components to maintain access. Reported discovery activity includes collection of system, user, and domain trust information. Observed persistence and post-compromise behavior indicate an operator focused on establishing durable access, monetizing compromised systems, and preparing environments for resale or additional intrusion activity. The actor has also demonstrated defense evasion through artifact deletion and process termination after payload deployment. Zebra2104 is best understood as an access-oriented cybercriminal actor rather than a state-sponsored espionage group. Its observed operations align with financially motivated intrusion activity centered on initial compromise, post-exploitation enablement, credential access, and resale or downstream use of victim network access.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a similar activity cluster to Prophet Spider; no additional operational details provided in this content beyond the comparison.
Referenced as a similar group to Prophet Spider; no additional operational details provided in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.