From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
Essential information
- Published
- 29/09/2025 16:37
- Modified
- 30/09/2025 08:46
- Tags
- 2025-09-29 backconnect brute ratel c4 cobalt strike credential harvesting data exfiltration javascript lateral movement latrodectus
- Related entities
- 1 intrusion sets (apt), 25 techniques (mitre), 4 malware
Description
A user executed a malicious JavaScript file linked to Lunar Spider, initiating a two-month intrusion. The file downloaded a Brute Ratel DLL, which then injected Latrodectus malware. The threat actor used various tools including Cobalt Strike, BackConnect, and a custom .NET backdoor for persistence and lateral movement. They harvested credentials from multiple sources and exfiltrated data using Rclone. The intrusion lasted nearly two months with intermittent C2 connections, discovery, lateral movement, and data theft. Despite comprehensive access to critical infrastructure, no ransomware deployment was observed.