TRAVELING SPIDER is a criminal group known for developing Nemty ransomware and exploiting Citrix Gateway for initial access.
Analyst brief
TRAVELING SPIDER is a criminal group tracked as the developer behind the Nemty ransomware. They primarily target organizations using single-factor authentication, exploiting Citrix Gateway to gain initial access. The group is known to send extortion-related emails through the victim's own Microsoft Office 365 instance. Defenders should enforce multi-factor authentication (MFA) on Citrix Gateway, monitor Office 365 for suspicious email rules, and prepare for Nemty ransomware encryption TTPs.
TRAVELING SPIDER
unknown
Crowdstrike Tracks the criminal developer of Nemty ransomware as TRAVELING SPIDER. The actor has been observed to take advantage of single-factor authentication to gain access to victim organizations through Citrix Gateway and send extortion-related emails using the victim’s own Microsoft Office 365 instance.