GURU SPIDER
Early in 2018, CrowdStrike Intelligence observed GURU SPIDER supporting the distribution of multiple crimeware families through its flagship malware loader, Quant Loader.
GURU SPIDER is a financially motivated cybercriminal group active since 2018, distributing multiple crimeware families through the Quant Loader.
GURU SPIDER is a threat actor active since early 2018, primarily operating as a cybercriminal group. They focus on financially motivated attacks, targeting a wide range of organizations. Their main TTP involves using their flagship malware loader, Quant Loader, to distribute multiple crimeware families. Defenders should prioritize monitoring for network anomalies, strengthening email security controls against initial infection vectors like phishing, and focusing on detecting multi-stage payload delivery chains.
Early in 2018, CrowdStrike Intelligence observed GURU SPIDER supporting the distribution of multiple crimeware families through its flagship malware loader, Quant Loader.
GURU SPIDER uses its flagship malware loader, Quant Loader, to distribute multiple crimeware families.
Defenders should strengthen email security controls against initial infection vectors like phishing.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.