Threat Actor Profile

Quantum Spider

Quantum Spider, also known by aliases MountLocker, SunRiseLocker, and AstroLocker, is a Big Game Hunting (BGH) adversary first observed in August 2020. Operating as a Ransomware-as-a-Service (RaaS), this group employs double extortion tactics, encrypting files and threatening to leak sensitive data if ransoms are not paid.


Threat Actor Profile

Quantum Spider

Fancy Bear TTPs

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Country of Origin

The exact country of origin for Quantum Spider is unknown. However, their operational patterns and infrastructure suggest potential ties to Eastern Europe, a common hub for ransomware groups.

Members

The group’s size is unknown, but it includes a core team of developers and a network of affiliates. Affiliates are responsible for initial compromises, data exfiltration, and ransomware deployment.

Leadership

No specific individuals or aliases have been publicly identified as leaders of Quantum Spider. The group operates under a decentralized RaaS model, with affiliates executing attacks.

Tactics

Quantum Spider targets large organizations, leveraging double extortion to maximize financial gain. They focus on industries like healthcare, finance, and government.


Techniques

The group uses phishing campaigns, exploits vulnerabilities in remote desktop protocols (RDP), and employs tools like CobaltStrike Beacon for lateral movement.


Procedures

Encrypts files using ChaCha20 and RSA-2048 encryption, exfiltrates sensitive data via FTP before encryption, and hosts TOR-based blogs to publicize stolen data and pressure victims.


Want to shut down threats before they start?

Indicators of Compromise (IOCs)

Organizations should monitor for:

  • Known Fancy Bear malware signatures (e.g., XAgent, ADVSTORESHELL).
  • Suspicious domains mimicking government or defense entities.
  • Zero-day exploits in applications like Microsoft Windows and Adobe Flash.
  • Abnormal network traffic patterns indicating command-and-control communications.

Key Victims

Fancy Bear targets include:

  • Governments (United States, Germany, France, Ukraine, and others).
  • Military Organizations (focus on NATO-aligned entities).
  • Media Outlets and Journalists (especially those covering Kremlin-related topics).
  • Critical Infrastructure (energy, aerospace, and defense).
  • International Sporting Organizations (e.g., WADA).
  • Political Groups (e.g., the Democratic National Committee).

Notable Cyber Attacks

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Notable Cyberattacks
  • 2020: Emergence of MountLocker ransomware, targeting diverse industries with double extortion tactics.

  • 2021: Rebranding as Quantum ransomware, with a TOR-based victim blog.

  • 2022: High-profile attacks leveraging updated ransomware variants.

Glitch effectGlitch effect

How to Defend Against Quantum Spider

1


Preventive Measures: Regularly update software, employ multi-factor authentication, and conduct phishing awareness training.


Huntress solutions help protect organizations by monitoring endpoints, detecting post-exploitation techniques, and mitigating threats with 24/7 managed detection and response.

Law Enforcement & Arrests

No arrests or law enforcement actions have been publicly reported against Quantum Spider members.


References

Related Threat Actor Profiles

Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.

Detect, Respond, Protect

See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.

Try Huntress for Free