Spidey Bot is referenced in the content as the name of a Discord webhook observed in a Web3/NFT phishing campaign. In the described case, a fake Gangster All Star NFT registration page attempted to load malicious JavaScript from Discord’s CDN, and extracted strings included access to https://discord.com/api/v9/users/@me and a Discord webhook URL (https://discord.com/api/webhooks/951908349677568091/4N7ccrI6NWBsD-Gw7BIs3MTyYm037ixS1iJvzwiQESe1z_gE6Se6j5JPMmQArspuJ4dF). Querying that webhook returned the name "Spidey Bot." The content explicitly links this naming to reporting about "Discord Spidey Bot" malware stealing usernames and passwords. High-confidence details directly supported by the content are limited to this association: Spidey Bot is tied to Discord-based credential theft activity and appeared in infrastructure used alongside phishing targeting Web3/NFT users. The broader campaign context involved fake NFT registration pages and Discord-hosted payload delivery, but the content does not provide a fuller standalone malware family profile, technical internals, or definitive actor attribution for Spidey Bot itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware referenced in connection with Discord that is described as stealing usernames and passwords; the analyzed phishing infrastructure includes a Discord webhook named “Spidey Bot,” suggesting use of Discord webhooks for data collection/exfiltration.
Referenced as malware associated with stealing Discord usernames and passwords via a phishing-related Discord webhook infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.