Detect, Respond, Protect
See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.
Quantum Spider, also known by aliases MountLocker, SunRiseLocker, and AstroLocker, is a Big Game Hunting (BGH) adversary first observed in August 2020. Operating as a Ransomware-as-a-Service (RaaS), this group employs double extortion tactics, encrypting files and threatening to leak sensitive data if ransoms are not paid.
Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.
Quantum Spider targets large organizations, leveraging double extortion to maximize financial gain. They focus on industries like healthcare, finance, and government.
The group uses phishing campaigns, exploits vulnerabilities in remote desktop protocols (RDP), and employs tools like CobaltStrike Beacon for lateral movement.
Encrypts files using ChaCha20 and RSA-2048 encryption, exfiltrates sensitive data via FTP before encryption, and hosts TOR-based blogs to publicize stolen data and pressure victims.
Organizations should monitor for:
Fancy Bear targets include:
Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.
2020: Emergence of MountLocker ransomware, targeting diverse industries with double extortion tactics.
2021: Rebranding as Quantum ransomware, with a TOR-based victim blog.
2022: High-profile attacks leveraging updated ransomware variants.
Preventive Measures: Regularly update software, employ multi-factor authentication, and conduct phishing awareness training.
Huntress solutions help protect organizations by monitoring endpoints, detecting post-exploitation techniques, and mitigating threats with 24/7 managed detection and response.
No arrests or law enforcement actions have been publicly reported against Quantum Spider members.
Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.