Spyder is a modular backdoor used in cyber-espionage operations and is associated in the provided reporting with multiple China- and South Asia-linked intrusion sets. It is described as part of the FishMonger toolset, alongside ShadowPad, Cobalt Strike, FunnySwitch, SprySOCKS, and BIOPASS RAT, and has also been reported as custom malware used by RedHotel. ESET reported Spyder as a backdoor typically used by FishMonger and observed it during Operation FishMedley, a 2022 campaign attributed with high confidence to FishMonger, a China-aligned APT assessed to be operated by the Chengdu-based contractor I-SOON under the broader Winnti Group umbrella. In that campaign, FishMonger targeted organizations in Taiwan, Hungary, Turkey, Thailand, the United States, and France, including government entities, NGOs, a geopolitical think tank, and Catholic organizations. At one Thailand victim, a Spyder loader was downloaded from a compromised internal web server as aa.doc and dropped as C:\Users\Public\task.exe. The Spyder payload used the hardcoded C2 server 61.238.103[.]165; multiple subdomains of junlper[.]com resolved to that IP in 2022, and junlper[.]com was identified as a known Spyder C2 domain designed as a homoglyph of juniper.net. A self-signed TLS certificate with thumbprint 89EDCFFC66EDA3AEB75E140816702F9AC73A75F0 was observed on port 443 of 61.238.103[.]165 from May to December 2022 and was previously associated with FishMonger. Separate reporting in the content states Spyder has similarities to a Spyder downloader used by Maha Grass and that StreamSpy was linked by QiAnXin to Patchwork because of similarities to Spyder, which that reporting describes as a variant of another backdoor named WarHawk attributed to SideWinder. The content does not provide a unified technical capability set for Spyder beyond identifying it as a modular implant/backdoor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Their toolkit includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, and the BIOPASS RAT, and expanding SprySOCKS to Windows clearly shows continued investment in offensive capability.
"We also found some similarities between this Trojan and the Spyder downloader used by Maha Grass."
5 distinct techniques documented for this family, organized by ATT&CK tactic.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of FishMonger’s toolkit.
FishMonger’s toolset includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, SprySOCKS, and the BIOPASS RAT.
A backdoor RAT variant used by Patchwork and SideWinder, supporting data collection and remote access.
Downloader referenced as previously used by 'Maha Grass'; mentioned due to similarities with StreamSpy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.