CLOCKWORK SPIDER
Opportunistic actor that installs custom root certificate on victim to support man-in-the-middle network monitoring.
source: misp-galaxy2 refs →
CLOCKWORK SPIDER is an opportunistic threat actor known for deploying custom root certificates to monitor network traffic.
CLOCKWORK SPIDER is an opportunistic threat actor that deploys a custom root certificate on victim systems to enable man-in-the-middle network monitoring. Defenders should focus on detecting unauthorized root certificate installations and anomalies in network traffic inspection.
Opportunistic actor that installs custom root certificate on victim to support man-in-the-middle network monitoring.
An opportunistic threat actor.
By installing a custom root certificate to monitor network traffic.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.