Wizard Spider

MITRE ATT&CK: G0102 View on attack.mitre.org

Aliases: UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, DEV-0237, Storm-0193, Trickbot LLC, UNC2053, Storm-0230, Wizard Spider, WIZARD SPIDER, Conti Team 1

First seen
2016-01-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:33:54

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:fr country_code:de

Context

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.

Detection coverage

  • 204 YARA rules
  • 796 Sigma rules

Malware & tools used

  • Exploitation of Remote Services (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Tool (attack-pattern)
  • Windows Service (attack-pattern)
  • SMB/Windows Admin Shares (attack-pattern)
  • Data Staged (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Process Injection (attack-pattern)
  • Remote Services (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Pass the Hash (attack-pattern)
  • Windows Permissions (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Malicious File (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • File Deletion (attack-pattern)
  • Group Policy Preferences (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Rundll32 (attack-pattern)
  • Kerberoasting (attack-pattern)

Reports & references

  • secureworks.com — How Cyber Adversaries Are Adapting To Exploit The Global Pandemic (report)
  • CrowdStrike — Big Game Hunting With Ryuk Another Lucrative Targeted Ransomware (report)
  • Mandiant — A Nasty Trick From Credential Theft Malware To Business Disruption (report)
  • labs.sentinelone.com — Top Tier Russian Organized Cybercrime Group Unveils Fileless Stealthy Powertrick Backdoor For High Value Targets (report)
  • CrowdStrike — Sin Ful Spiders Wizard Spider And Lunar Spider Sharing The Same Web (report)
  • CrowdStrike — Wizard Spider Lunar Spider Shared Proxy Module (report)
  • CrowdStrike — Wizard Spider Adds New Feature To Ryuk Ransomware (report)
  • cybereason.com — Dropping Anchor From A Trickbot Infection To The Discovery Of The Anchor Malware (report)
  • secureworks.com — Gold Ulrick (report)
  • secureworks.com — Dyre Banking Trojan (report)
  • secureworks.com — Trickbot Modifications Target Us Mobile Users (report)
  • secureworks.com — Gold Blackburn (report)
  • strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
  • prodaft.com — Wizardspider Tlpwhite V.1.4 (report)
  • securityintelligence.com — Itg23 Crypters Cooperation Between Cybercriminal Groups (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G0102 (report)
  • securityintelligence.com — Trickbot Gang Doubles Down Enterprise Infection (report)
  • CISA — Aa20 302A (report)
  • web.archive.org — Fin12 Group Profile (report)
  • CrowdStrike — Timelining Grim Spiders Big Game Hunting Tactics (report)
  • CrowdStrike — Wizard Spider Adversary Update (report)

Attributed from

  • FIN12 March 2023 Hospital Center Intrusion (campaign)

External references