Chaotic Spider


CHAOTIC SPIDER is a criminal actor—operating under the moniker Desorden—who has been active on English-language cybercriminal forums since September 2021. The adversary attempts to sell exfiltrated data from targets located in Southeast Asia across multiple sectors. CHAOTIC SPIDER does not have unique malware or tooling, but instead relies on SQL injections against vulnerable web-facing servers to...

Community Identifiers



  • 0Fo3Us869RldAqE


  • HWYjnBcz

Contact our team about
IOCs for this adversary


During a cybersecurity incident, indicators of compromise (IoC) are clues and evidence of a data breach.