CrowdStrike reported that CARBON SPIDER, a financially motivated threat actor long associated with large-scale payment card theft and cybercrime operations, shifted toward big-game hunting by targeting enterprises with hands-on intrusions that can enable ransomware deployment. The group was described as evolving beyond opportunistic fraud activity and adopting tactics more commonly seen in enterprise-focused extortion campaigns, including deeper network access, credential abuse, and post-compromise movement inside victim environments.
The reporting links CARBON SPIDER to a broader criminal maturation in which established eCrime actors repurpose their access, tooling, and operational discipline to pursue higher-value corporate targets. The activity highlights a threat model in which actors known for banking and carding operations increasingly pursue enterprise compromise for larger payouts, raising the risk that organizations facing an initial financially motivated intrusion may quickly confront full-scale ransomware or extortion operations.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
CrowdStrike published a blog post analyzing how the CARBON SPIDER threat actor had embraced big game hunting tactics. The reference indicates this reporting was released on August 30, 2021.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.