Last seven days
- First activity
- Sep 4, 2026
- Last activity
- Sep 4, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
LUNAR SPIDER is a Russian-speaking, financially motivated cybercrime threat actor associated primarily with the development and operation of IcedID, also known as BokBot, and the newer Latrodectus malware family.
Profile source: Mallory opens in a new tabLunar Spider
LUNAR SPIDER is a Russian-speaking, financially motivated cybercrime threat actor associated primarily with the development and operation of IcedID, also known as BokBot, and the newer Latrodectus malware family. The group has been active since at least 2009 and is also tracked as GOLD SWATHMORE. LUNAR SPIDER operates as an initial-access and malware-delivery actor within the broader eCrime ecosystem and has longstanding ties to other major Russian-speaking cybercriminal clusters, including operators associated with TrickBot, Conti, and ALPHV/BlackCat.
LUNAR SPIDER was the first known group to distribute IcedID in 2017. IcedID began as a banking trojan and evolved into a widely used access malware platform that enabled hands-on intrusions and follow-on ransomware activity. Around 2020, the group expanded IcedID availability to outside threat groups for use in ransomware campaigns, reinforcing its role as an access broker and malware service provider. More recently, LUNAR SPIDER has been linked with Latrodectus, a lightweight loader and backdoor widely assessed as a successor or replacement for IcedID after law-enforcement disruption of parts of the IcedID ecosystem in 2024.
The actor’s delivery methods include phishing, thread hijacking, malicious advertising, SEO poisoning, fake software-update lures, fake CAPTCHA and ClickFix-style social engineering, and script- or MSI-based infection chains that culminate in DLL execution through rundll32. Observed campaigns have used heavily obfuscated JavaScript downloaders, malicious installers, and brand impersonation to compromise victims. LUNAR SPIDER has also abused Telegram for victim-click monitoring in FakeCaptcha workflows tied to Latrodectus delivery.
Operationally, LUNAR SPIDER demonstrates strong initial-access, persistence, reconnaissance, credential-theft, and post-exploitation capabilities. Malware associated with the group has been used to profile hosts, steal credentials and browser data, establish persistence through scheduled tasks or autorun mechanisms, and deliver secondary tooling including Brute Ratel C4, BackConnect remote-access modules, and IcedID itself. Latrodectus-linked intrusions have led directly to interactive hands-on-keyboard activity, including deployment of remote-access tooling that supports reverse shell, file management, and remote desktop-style control.
LUNAR SPIDER is closely associated with ransomware enablement rather than operation of a branded ransomware program of its own. Its malware has repeatedly served as a precursor to ransomware intrusions, and the group has been assessed as providing initial access to ransomware operators including WIZARD SPIDER-linked operations and ALPHV/BlackCat affiliates. Reporting also links the actor to cooperation with other cybercriminal groups that have used IcedID to gain footholds before lateral movement, data theft, and ransomware deployment.
Known aliases include GOLD SWATHMORE and variants of LunarSpider/Lunar Spider. High-confidence reporting characterizes the group as a mature Russian-speaking eCrime actor specializing in malware development, access brokerage, and enabling downstream financially motivated intrusions, particularly against the financial sector in recent Latrodectus and Brute Ratel campaigns.
Samples
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.