SYMBOLCOMMON_NAMEaka. SYNONYMS

BOSS SPIDER  (Back to overview)

aka: GOLD LOWELL

Throughout 2018, CrowdStrike Intelligence tracked BOSS SPIDER as it regularly updated Samas ransomware and received payments to known Bitcoin (BTC) addresses. This consistent pace of activity came to an abrupt halt at the end of November 2018 when the U.S. DoJ released an indictment for Iran-based individuals Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri, alleged members of the group.


Associated Families

There are currently no families associated with this actor.


References
2020-01-01SecureworksSecureWorks
GOLD LOWELL
SamSam BOSS SPIDER
2019-01-01CrowdStrikeCrowdStrike
2019 CrowdStrike Global Threat Report
APT40 BOSS SPIDER FIN6 Flash Kitten GURU SPIDER LUNAR SPIDER NOMAD PANDA PINCHY SPIDER RATPAK SPIDER SALTY SPIDER TINY SPIDER
2019-01-01CrowdStrikeCrowdStrike
2019 CrowdStrike Global Threat Report
BOSS SPIDER Flash Kitten GURU SPIDER LUNAR SPIDER NOMAD PANDA PINCHY SPIDER RATPAK SPIDER SALTY SPIDER TINY SPIDER
2018-02-15SecureworksCounter Threat Unit ResearchTeam
SamSam Ransomware Campaigns
MimiKatz reGeorg SamSam BOSS SPIDER
2018-02-15SecureworksCounter Threat Unit ResearchTeam
SamSam: Converting Opportunity into Profit
SamSam BOSS SPIDER
2016-05-03SecureworksKevin Strickland
The Continuing Evolution of Samas Ransomware
SamSam BOSS SPIDER
2016-03-30SecureworksCounter Threat Unit ResearchTeam
Ransomware Deployed by Adversary with Established Foothold
MimiKatz reGeorg SamSam BOSS SPIDER

Credits: MISP Project