Spyder is a backdoor associated with PRC-linked cyber-espionage activity. It has been used by APT41 and FishMonger/RedHotel (also tracked under several Winnti ecosystem aliases) and has appeared alongside ShadowPad, Winnti, Cobalt Strike, FunnySwitch, and other bespoke implants. Spyder has been characterized as a modular implant and exhibits code-level similarity in command-data handling to the Winnti 4.0 Worker component, suggesting a technical relationship within that tooling ecosystem. It has been observed in espionage intrusions against government and other strategically relevant organizations, including campaigns affecting organizations in Asia, Europe, and North America. Spyder uses command-and-control infrastructure, including encrypted network communications, to support remote operator access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Earth Lusca [is] known to rely heavily on Cobalt Strike, ShadowPad, Winnti and Spyder malware families.
Spyder and ReverseWindow are APT malware utilized by PRC-linked cyber espionage threat actors (respectively APT41 and LuoYu).
"We also found some similarities between this Trojan and the Spyder downloader used by Maha Grass."
7 distinct techniques documented for this family, organized by ATT&CK tactic.
For years, I have reversed the C2 protocols of high-profile APT malware families then, by emulating the protocols, discovered the active C2 servers on the Internet... both pieces of malware support multiple C2 protocols, such as TCP / TLS / HTTP / HTTPS / UDP.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of FishMonger’s toolkit.
FishMonger’s toolset includes ShadowPad, Spyder, Cobalt Strike, FunnySwitch, SprySOCKS, and the BIOPASS RAT.
A backdoor RAT variant used by Patchwork and SideWinder, supporting data collection and remote access.
Downloader referenced as previously used by 'Maha Grass'; mentioned due to similarities with StreamSpy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.