ANTHROPOID SPIDER — Ransomware Profile

ANTHROPOID SPIDER is CrowdStrike's designation for the financially motivated criminal group publicly tracked as EmpireMonkey, active since at least October 2018 and focused on stealing funds and financial data from banks and from the software and service providers that support them; CrowdStrike classifies it as eCrime with a criminal motivation and a financial-gain objective. In February and March 2019 the group ran phishing campaigns spoofing French, Norwegian and Belizean financial regulators, using macro-enabled Microsoft Office documents to deliver the PowerShell Empire framework and Cobalt Strike, and it likely enabled a breach that allegedly involved fraudulent transfers over the SWIFT network. Kaspersky ties the same activity to the suspected theft of about EUR 13 million from Bank of Valletta in Malta in February 2019 and reports it under a combined 'CobaltGoblin/Carbanak/EmpireMonkey' label, judging that this cluster shares tooling and infrastructure with FIN7 but is operated by a different team. No vendor attributes the group to a state or to a country of origin, and no public reporting describes it deploying ransomware.

Also tracked as

Empire Monkey, CobaltGoblin

Tools & malware

Vendor research

Read the full analysis on IntelFusions