Prophet Spider
Aliases: GOLD MELODY, UNC961
- First seen
- 2017-05-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:04:13
Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical education-and-nonprofits
Context
PROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web servers, which commonly involves leveraging a variety of publicly disclosed vulnerabilities. The adversary has likely functioned as an access broker — handing off access to a third party to deploy ransomware — in multiple instances.
Detection coverage
- 7 YARA rules
Malware & tools used
- Egregor (malware)
- Mount Locker (malware)
Reports & references
- CrowdStrike — Prophet Spider Exploits Oracle Weblogic To Facilitate Ransomware Activity (report)
- CrowdStrike — Prophet Spider Exploits Citrix Sharefile (report)
- secureworks.com — Gold Melody Profile Of An Initial Access Broker (report)
- Mandiant — Unc961 Multiverse Financially Motivated (report)