RATPAK SPIDER is a threat actor known for leaking the Pegasus malware framework, primarily targeting Russia's financial sector.
Analyst brief
RATPAK SPIDER is a threat actor known for the July 2018 leak of their Pegasus malware framework, primarily targeting Russia's financial sector. The associated Buhtrap malware has been observed in SWC campaigns also aimed at Russian users. Key TTPs involve the use of leaked source code and targeted malware operations against financial institutions. Defenders should focus on monitoring for indicators linked to the Pegasus and Buhtrap malware, particularly anomalous banking trojan activity targeting the financial sector.
RATPAK SPIDER
unknown
In July 2018, the source code of Pegasus, RATPAK SPIDER’s malware framework, was anonymously leaked. This malware has been linked to the targeting of Russia’s financial sector. Associated malware, Buhtrap, which has been leaked previously, was observed this year in connection with SWC campaigns that also targeted Russian users.