ANTHROPOID SPIDER
Aliases: Empire Monkey, CobaltGoblin
- First seen
- 2019-02-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:49:54
Targeted industries: financial-services
Targeted regions: country_code:fr country_code:no country_code:bz
Context
Publicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian and Belizean financial regulators and institutions. These campaigns used macro-enabled Microsoft documents to deliver the PowerShell Empire post-exploitation framework. ANTHROPOID SPIDER likely enabled a breach that allegedly involved fraudulent transfers over the SWIFT network.
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- kaspersky.com — 2019 Fin7 Hacking Group Targets More Than 130 Companies After Leaders Arrest (report)
- fortiguard.com — 7630456 (report)