PROPHET SPIDER is an eCrime access broker targeting vulnerable web servers for ransomware deployment.
Analyst brief
PROPHET SPIDER, also tracked as GOLD MELODY and UNC961, is an eCrime threat actor active since at least May 2017. The actor primarily targets and compromises vulnerable web servers by exploiting publicly disclosed vulnerabilities. It has frequently operated as an access broker, selling initial access to third parties for subsequent ransomware deployment. Defenders should prioritize patching internet-facing web applications, monitoring for web-shell activity, and inspecting for anomalous C2 traffic to suspicious external IPs.
Prophet Spider
GOLD MELODYUNC961
unknown
PROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web servers, which commonly involves leveraging a variety of publicly disclosed vulnerabilities. The adversary has likely functioned as an access broker — handing off access to a third party to deploy ransomware — in multiple instances.
What type of threat actor is PROPHET SPIDER and what is its primary objective?+
PROPHET SPIDER is an eCrime actor that has frequently operated as an access broker, selling initial access to a third party, which is often used for subsequent ransomware deployment.
What is the primary method used by PROPHET SPIDER to gain access to target systems?+
PROPHET SPIDER primarily gains access by targeting and compromising vulnerable web servers through the exploitation of publicly disclosed vulnerabilities.