BOSS SPIDER (GOLD LOWELL) is a cybercriminal group known for updating Samas ransomware and collecting Bitcoin ransoms.
Analyst brief
BOSS SPIDER (also tracked as GOLD LOWELL) is a cybercriminal group that actively updated the Samas ransomware and received payments to known Bitcoin addresses throughout 2018. Their operations ceased abruptly in late November 2018 following a U.S. DoJ indictment of Iran-based individuals. While a specific victim profile is not detailed, the group is presumed to target organizations for financial gain consistent with ransomware campaigns. Key TTPs involve the use of custom Samas ransomware for extortion and Bitcoin for ransom collection; defenders should focus on detecting ransomware deployment indicators, especially those enabling lateral movement within networks.
BOSS SPIDER
GOLD LOWELL
unknown
Throughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known Bitcoin (BTC) addresses. This consistent pace of activity came to an abrupt halt at the end of November 2018 when the U.S. DoJ released an indictment for Iran-based individuals Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri, alleged members of the group.
The BOSS SPIDER group used the Samas ransomware and regularly updated it throughout 2018.
Why did BOSS SPIDER's activity stop at the end of 2018?+
BOSS SPIDER's activity came to an abrupt halt at the end of November 2018 after the U.S. Department of Justice released an indictment against Iran-based individuals.