Prophet Spider — Ransomware Profile
Prophet Spider is the CrowdStrike name for a financially motivated intrusion set that has been breaking into internet-facing servers since at least May 2017; Secureworks tracks overlapping activity as GOLD MELODY and Mandiant as UNC961. Rather than encrypting networks itself, the group resells footholds: CrowdStrike assessed with low confidence that it hands compromised environments to ransomware operators, and Secureworks characterises it outright as an initial access broker. Its route in is almost always an unpatched public application, with CrowdStrike documenting exploitation of Oracle WebLogic (CVE-2020-14882 and CVE-2020-14750) and a Citrix ShareFile path-traversal flaw (CVE-2021-22941), while Secureworks adds Apache Struts, JBoss, Sitecore and both Log4j issues to the list. After exploitation the operators favour JSP and ASPX web shells, then reach for Mimikatz, WinExe, the reGeorg proxy and the GOTROJ remote access trojan, with a habitual reliance on wget acting as a tell across otherwise varied intrusions. Ransomware deployed behind its access includes Egregor in 2020 and MountLocker in 2021 per CrowdStrike, with Secureworks additionally recording CryptoDefense and observing the group still operating into early 2023.Also tracked as
GOLD MELODY, UNC961
Vendor research
- PROPHET SPIDER Exploits Citrix ShareFile Remote Code Execution Vulnerability CVE-2021-22941 to Deliver Webshell CrowdStrike
- GoldMelody's Hidden Chords: Initial Access Broker In-Memory IIS Modules Revealed Unit 42 (Palo Alto Networks)
- UNC961 in the Multiverse of Mandiant: Three Encounters with a Financially Motivated Threat Actor Mandiant (Google Threat Intelligence)
- GOLD MELODY: Profile of an Initial Access Broker Secureworks Counter Threat Unit
- PROPHET SPIDER Exploits Oracle WebLogic to Facilitate Ransomware Activity CrowdStrike