Prophet Spider

Aliases: GOLD MELODY, UNC961

First seen
2017-05-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:04:13

Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical education-and-nonprofits

Context

PROPHET SPIDER is an eCrime actor, active since at least May 2017, that primarily gains access to victims by compromising vulnerable web servers, which commonly involves leveraging a variety of publicly disclosed vulnerabilities. The adversary has likely functioned as an access broker — handing off access to a third party to deploy ransomware — in multiple instances.

Detection coverage

  • 7 YARA rules

Malware & tools used

Reports & references

  • CrowdStrike — Prophet Spider Exploits Oracle Weblogic To Facilitate Ransomware Activity (report)
  • CrowdStrike — Prophet Spider Exploits Citrix Sharefile (report)
  • secureworks.com — Gold Melody Profile Of An Initial Access Broker (report)
  • Mandiant — Unc961 Multiverse Financially Motivated (report)

External references