ANTHROPOID SPIDER is a threat actor that deployed PowerShell Empire via phishing campaigns targeting the finance sector.
Analyst brief
ANTHROPOID SPIDER, also known as 'Empire Monkey', is a threat actor that targeted the finance sector in early 2019 through phishing campaigns. These campaigns spoofed French, Norwegian, and Belizean regulators using macro-enabled Microsoft documents to deliver the PowerShell Empire post-exploitation framework. Key TTPs include leveraging malicious macros and PowerShell Empire, which likely enabled fraudulent SWIFT transfers. Defenders should focus on detecting phishing attempts, restricting macro execution, and monitoring for unusual PowerShell activity.
ANTHROPOID SPIDER
Empire MonkeyCobaltGoblin
unknown
Publicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian and Belizean financial regulators and institutions. These campaigns used macro-enabled Microsoft documents to deliver the PowerShell Empire post-exploitation framework. ANTHROPOID SPIDER likely enabled a breach that allegedly involved fraudulent transfers over the SWIFT network.