spwebmember is a bespoke Microsoft .NET SharePoint enumeration and data-dumping tool used by APT15 (also known as Ke3chang, Mirage, Vixen Panda, GREF, and Playful Dragon). In the reported May 2017 compromise investigated by NCC Group, APT15 used spwebmember during an intrusion against a UK Government services provider, where the attackers stole sensitive documents and were assessed to be targeting information related to UK government departments and military technology. The tool was described as a custom SharePoint utility containing hardcoded client project name values for data extraction. It connects directly to the SQL SharePoint database and issues queries to dump all data to a temporary file with a filename suffix of "spdata." The content does not provide specific hashes or standalone network indicators for spwebmember itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...a bespoke Microsoft SharePoint enumeration and data dumping tool, known as ‘spwebmember’.
1 distinct technique documented for this family, organized by ATT&CK tactic.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Bespoke .NET tool used to enumerate SharePoint and dump data by connecting to the SQL SharePoint database and exporting query results to a temporary file (affixed with 'spdata'); includes hardcoded client project names for targeted extraction.
Bespoke .NET tool used to enumerate Microsoft SharePoint and dump data by querying the SharePoint SQL database and writing output to temporary files (with 'spdata' suffix).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.