Sly Spider


SLY SPIDER operates the Gozi ISFB as a Malware-as-a-Service (MaaS) and the WhiteRabbit/RansomHouse ransomware group. The adversary advertises the Gozi ISFB MaaS on online criminal forums and has also partnered with other adversaries, such as SMOKY SPIDER and APOTHECARY SPIDER, to further promote the malware. CrowdStrike Intelligence has identified several SLY SPIDER customers who use Gozi ISFB for...


  • bCiV5lKXjs3mwa0


  • Q308V4E2

Contact our team about
IOCs for this adversary


During a cybersecurity incident, indicators of compromise (IoC) are clues and evidence of a data breach.