Spyder
- First seen
- 2018-06-01 00:00:00
- Malware type
- spyware, backdoor
- Family
- Malware family
- Last IoC activity
- 2026-05-24 01:57:56
- Profile updated
- 2026-07-07 13:01:52
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Spyder is a malware family known for its espionage capabilities. It installs spyware and backdoors on targeted systems to exfiltrate sensitive information.
Detection coverage
- 2 YARA rules
Detection rules
- MALPEDIA_Win_Spyder_Patchwork_Auto (yara-rule)
- MALPEDIA_Win_Spyder_Auto (yara-rule)
Reports & references
- hello.global.ntt — The Operations Of Winnti Group (report)
- recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)
- go.recordedfuture.com — Cta 2023 0808 (report)
- youtube.com — Watch (report)
- ESET — Operation Fishmedley (report)
- speakerdeck.com — Winnti Is Coming Evolution After Prosecution At Hitcon2021 (report)
- cybereason.com — Operation Cuckoobees Deep Dive Into Stealthy Winnti Techniques (report)
- cybereason.com — Operation Cuckoobees A Winnti Malware Arsenal Deep Dive (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Spyder (report)
- vms.drweb.com — Virus (report)
- st.drweb.com — Backdoor.Spyder.1 En (report)
- securitynews.sonicwall.com — Chinas Winnti Spyder Module (report)