BOSS SPIDER

Aliases: GOLD LOWELL

First seen
2016-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 11:51:30

Targeted industries: healthcare-and-pharmaceutical education-and-nonprofits government-and-public-sector

Targeted regions: country_code:us country_code:gb country_code:de

Context

Throughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known Bitcoin (BTC) addresses. This consistent pace of activity came to an abrupt halt at the end of November 2018 when the U.S. DoJ released an indictment for Iran-based individuals Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri, alleged members of the group.

Reports & references

  • CrowdStrike — 2019 Crowdstrike Global Threat Report (report)
  • secureworks.com — Gold Lowell (report)
  • secureworks.com — Samsam Converting Opportunity Into Profit (report)
  • secureworks.com — Samas Ransomware (report)
  • secureworks.com — Ransomware Deployed By Adversary (report)
  • secureworks.com — Samsam Ransomware Campaigns (report)

External references