Lunar Spider, a sophisticated cybercrime group, executed a highly targeted intrusion campaign that began with a single-click attack on a Windows system. The attack was initiated when a user was deceived into opening a JavaScript file disguised as a tax form, which triggered the remote download of an MSI package. This package subsequently launched a Brute Ratel DLL using the rundll32 Windows utility, marking the start of a multi-stage compromise. The attackers quickly injected the Latrodectus malware, which enabled the retrieval of a specialized credential stealer module. Within the first hour, credentials from over two dozen Chromium-based browsers were harvested, along with Microsoft Outlook email and server configurations. The threat actors escalated privileges by running the Isassa.exe binary, granting them high-level access to the domain environment. Throughout the nearly two-month intrusion, Lunar Spider employed a variety of malware, including Brute Ratel C4, Cobalt Strike, BackConnect, and a custom .NET backdoor, to maintain persistence and evade detection. The attackers utilized multiple evasion and persistence mechanisms, ensuring intermittent command and control connections and ongoing access to the compromised environment. Data exfiltration was conducted using Rclone and FTP, with significant file share server data stolen by the twentieth day of the compromise. The operation demonstrated advanced lateral movement and discovery techniques, as the attackers systematically explored the network and harvested credentials from sources such as LSASS, backup software, and Windows Answer files. The campaign highlighted the use of living-off-the-land techniques and the deployment of multiple malware families to achieve their objectives. The incident underscores the importance of user awareness, as the entire compromise stemmed from a single deceptive email attachment. The attackers' ability to maintain access for nearly two months without detection illustrates the sophistication of their tactics and the challenges defenders face. The use of Brute Ratel and Cobalt Strike, both advanced post-exploitation frameworks, enabled the attackers to blend in with legitimate administrative activity. The incident also revealed the threat group's focus on persistence, with multiple fallback mechanisms in place to reestablish access if disrupted. The detailed forensic analysis provided by incident responders offers valuable insights into the attack chain, detection opportunities, and recommended defensive measures. Organizations are advised to enhance email security, monitor for suspicious script execution, and implement robust credential protection strategies to mitigate similar threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
On September 30, 2025, SC Media summarized the DFIR findings, highlighting that a single user click enabled a Windows compromise attributed to Lunar Spider. The coverage emphasized the attack chain and prolonged access described in the underlying report.
On September 29, 2025, The DFIR Report published a case study detailing the near two-month intrusion, its tooling, and its links to the Lunar Spider and Latrodectus ecosystem. The report provided technical details on initial access, persistence, lateral movement, and exfiltration.
On October 30, 2024, reporting described a recent LUNAR SPIDER campaign targeting financial-sector victims via malvertising and SEO-poisoned tax-themed lures that delivered an obfuscated Latrodectus JavaScript loader, MSI installer, and Brute Ratel C4. The analysis also documented persistence through a Windows Run key and infrastructure overlaps linking Latrodectus with IcedID and ransomware-associated ecosystems.
The actor maintained intermittent command-and-control access for almost two months using BackConnect, Latrodectus, Brute Ratel, and Cobalt Strike before being evicted from the environment. No ransomware deployment was observed during the incident.
In June 2024, tax-themed campaigns reappeared using Latrodectus v1.3 together with Brute Ratel after the Operation Endgame disruption. The report links this resurgence to the broader Lunar Spider and Latrodectus tradecraft ecosystem.
Later in the intrusion, the actor targeted backup infrastructure by running Veeam-Get-Creds.ps1 and conducted network scanning with rustscan. These actions suggested preparation for additional access or impact, although no ransomware deployment was observed.
From May 27 to May 29, 2024, Operation Endgame disrupted infrastructure associated with Latrodectus. The DFIR report cites this law enforcement action as relevant to the broader ecosystem tied to the intrusion.
On day 20 of the intrusion, the actor exfiltrated data from a file share server using a renamed rclone binary over FTP for roughly 10 hours. This marked a significant impact phase of the compromise.
During the intrusion, the threat actor also tried further lateral movement using a custom Zerologon exploit tool, zero.exe, targeting CVE-2020-1472, along with a failed Metasploit remote-service attempt. These efforts reflected continued expansion attempts inside the victim network.
After escalating privileges, the actor moved laterally with PsExec following an unsuccessful WMIC attempt, deployed multiple Cobalt Strike beacons, and installed a custom .NET backdoor named lsassa.exe for scheduled-task persistence and command-and-control.
By the third day of the intrusion, the actor recovered plaintext domain administrator credentials from an exposed unattend.xml Windows Answer file. This enabled rapid privilege escalation and broader Active Directory reconnaissance with AdFind.
Within hours of the initial infection, the threat actor deployed BackConnect/VNC to obtain interactive remote access to the environment. This expanded their ability to operate persistently on compromised systems.
Shortly after initial compromise, Latrodectus established command-and-control through multiple Cloudflare-proxied domains and retrieved a stealer module. The actor then performed host and domain reconnaissance using built-in Windows commands.
In May 2024, the intrusion began when a user executed a heavily obfuscated tax-themed malicious JavaScript file linked to the Lunar Spider initial access ecosystem. The script downloaded an MSI that launched a Brute Ratel DLL through rundll32, which then injected the Latrodectus downloader into explorer.exe.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 122 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethedfirreport.com
Open sourcecontagiodump.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.