BushidoUK RVM Profile: ProphetSpider

Fecha
18 Jun 2026
Actor
prophetspider
Tipo
Threat-actor
Pais
United Kingdom
Sector
-
Confianza
high
65
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

3IOCs
0TTPs
prophetspiderActor
United KingdomPais
Executive Summary
Perfil del grupo ransomware segun BushidoUK Ransomware Vulnerability Matrix. Incluye vulnerabilidades conocidas, herramientas y TTPs asociadas.

Key Points

  • Source: BushidoUK RVM GroupProfiles
  • BushidoUK RVM Repository

Group Profile: ProphetSpider

Perfil del grupo ransomware segun BushidoUK Ransomware Vulnerability Matrix. Incluye vulnerabilidades conocidas, herramientas y TTPs asociadas.

Prophet Spider's Exploited Vulnerabilities

> [!NOTE]

> This is the list of vulnerabilities that have been observed during intrusions by Prophet Spider (aka GOLD MELODY and UNC961), the initial access broker (IAB) that has helped ransomware deployment, such as MAZE, Egregor, or MountLocker

Apache

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| Log4j | CVE-2021-44228 ("Log4Shell") | *Prophet Spider | secureworks.com |

| Log4j | CVE-2021-4104 | *Prophet Spider | secureworks.com |

| Struts | CVE-2017-5638 | *Prophet Spider | secureworks.com |

Citrix

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| ShareFile Storage Zones Controller | CVE-2021-22941 | *Prophet Spider | crowdstrike.com |

Java Applications

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| Jboss Application Server | CVE-2017-7504 | *Prophet Spider | secureworks.com |

Oracle

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| WebLogic | CVE-2020-14882 | *Prophet Spider | secureworks.com |

| WebLogic | CVE-2020-14750 | *Prophet Spider | secureworks.com |

| E-Business | CVE-2016-0545 | *Prophet Spider | secureworks.com |

Sitecore

| Product | CVE(s) | Ransomware Group(s) | Source(s) |

|---|---|---|---|

| Sitecore XP | CVE-2021-42237 | *Prophet Spider | secureworks.com |

---

#### Sources

| Date Published | Report |

|---|---|

| 20 September 2023 | https://www.secureworks.com/research/gold-melody-profile-of-an-initial-access-broker |

| 23 March 2023 | https://cloud.google.com/blog/topics/threat-intelligence/unc961-multiverse-financially-motivated |

| 7 March 2022 | https://www.crowdstrike.com/blog/prophet-spider-exploits-citrix-sharefile |

| 4 August 2021 | https://www.crowdstrike.com/blog/prophet-spider-exploits-oracle-weblogic-to-facilitate-ransomware-activity |

Referencias

Diamond Model

Adversary
prophetspider
Ver perfil →
Victim
BushidoUK RVM Profile: ProphetSpider
United Kingdom
Capability
Threat-actor
Infrastructure
www.secureworks.com
cloud.google.com
www.crowdstrike.com

Indicadores de Compromiso (IOCs)

TipoValorContextoOSINT
Domain www.secureworks.com Extraido del contenido VT OffSec SOCRadar
Domain cloud.google.com Extraido del contenido VT OffSec SOCRadar
Domain www.crowdstrike.com Extraido del contenido VT OffSec SOCRadar

Referencias y enlaces

→ Perfil del actor prophetspider en el blog → Ver prophetspider en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: raw.githubusercontent.com → Buscar prophetspider en APTTrail → Repositorio APTTrail → Mas incidentes en United Kingdom → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
← Volver al panel de inteligencia

Incidentes recientes