Prophet Spider — Ransomware Profile

Prophet Spider is the CrowdStrike name for a financially motivated intrusion set that has been breaking into internet-facing servers since at least May 2017; Secureworks tracks overlapping activity as GOLD MELODY and Mandiant as UNC961. Rather than encrypting networks itself, the group resells footholds: CrowdStrike assessed with low confidence that it hands compromised environments to ransomware operators, and Secureworks characterises it outright as an initial access broker. Its route in is almost always an unpatched public application, with CrowdStrike documenting exploitation of Oracle WebLogic (CVE-2020-14882 and CVE-2020-14750) and a Citrix ShareFile path-traversal flaw (CVE-2021-22941), while Secureworks adds Apache Struts, JBoss, Sitecore and both Log4j issues to the list. After exploitation the operators favour JSP and ASPX web shells, then reach for Mimikatz, WinExe, the reGeorg proxy and the GOTROJ remote access trojan, with a habitual reliance on wget acting as a tell across otherwise varied intrusions. Ransomware deployed behind its access includes Egregor in 2020 and MountLocker in 2021 per CrowdStrike, with Secureworks additionally recording CryptoDefense and observing the group still operating into early 2023.

Also tracked as

GOLD MELODY, UNC961

Vendor research

Read the full analysis on IntelFusions