ANTHROPOID SPIDER

Aliases: Empire Monkey, CobaltGoblin

First seen
2019-02-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 11:49:54

Targeted industries: financial-services

Targeted regions: country_code:fr country_code:no country_code:bz

Context

Publicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian and Belizean financial regulators and institutions. These campaigns used macro-enabled Microsoft documents to deliver the PowerShell Empire post-exploitation framework. ANTHROPOID SPIDER likely enabled a breach that allegedly involved fraudulent transfers over the SWIFT network.

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • kaspersky.com — 2019 Fin7 Hacking Group Targets More Than 130 Companies After Leaders Arrest (report)
  • fortiguard.com — 7630456 (report)

External references