Spyder

First seen
2018-06-01 00:00:00
Malware type
spyware, backdoor
Family
Malware family
Last IoC activity
2026-05-24 01:57:56
Profile updated
2026-07-07 13:01:52

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Spyder is a malware family known for its espionage capabilities. It installs spyware and backdoors on targeted systems to exfiltrate sensitive information.

Detection coverage

  • 2 YARA rules

Detection rules

  • MALPEDIA_Win_Spyder_Patchwork_Auto (yara-rule)
  • MALPEDIA_Win_Spyder_Auto (yara-rule)

Reports & references

  • hello.global.ntt — The Operations Of Winnti Group (report)
  • recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)
  • go.recordedfuture.com — Cta 2023 0808 (report)
  • youtube.com — Watch (report)
  • ESET — Operation Fishmedley (report)
  • speakerdeck.com — Winnti Is Coming Evolution After Prosecution At Hitcon2021 (report)
  • cybereason.com — Operation Cuckoobees Deep Dive Into Stealthy Winnti Techniques (report)
  • cybereason.com — Operation Cuckoobees A Winnti Malware Arsenal Deep Dive (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Spyder (report)
  • vms.drweb.com — Virus (report)
  • st.drweb.com — Backdoor.Spyder.1 En (report)
  • securitynews.sonicwall.com — Chinas Winnti Spyder Module (report)

External references