MUMMY SPIDER, also known by aliases such as TA542 and Mealybug, is a financially motivated cybercriminal group first identified in mid-2014. The group is primarily responsible for the development, operation, and distribution of the Emotet malware, which initially functioned as a banking trojan before evolving into a modular botnet and malware-as-a-service (MaaS) platform. This group is noted for its ability to enable large-scale ransomware campaigns by renting access to compromised systems to other criminal entities. Assessed with moderate confidence to be of Russian origin, MUMMY SPIDER is distinguished by its sophisticated email-based distribution campaigns, including the use of thread hijacking and timely lures such as COVID-19 themes, and its pattern of operating in bursts with periods of hiatus followed by the release of new Emotet variants. The group's operational resilience is evident in its repeated resurfacing following law enforcement disruptions, continuously refining its at
T1033 - System Owner/User Discovery, T1036.005 - Match Legitimate Name or Location, T1053.005 - Scheduled Task, T1106, T1132.001 - Standard Encoding, T1055