Wizard Spider
MITRE ATT&CK: G0102 View on attack.mitre.org
Aliases: UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, DEV-0237, Storm-0193, Trickbot LLC, UNC2053, Storm-0230, Wizard Spider, WIZARD SPIDER, Conti Team 1
- First seen
- 2016-01-01 00:00:00
- Origin
- RU
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:33:54
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:fr country_code:de
Context
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.
Detection coverage
- 204 YARA rules
- 796 Sigma rules
Malware & tools used
- Exploitation of Remote Services (attack-pattern)
- Archive via Utility (attack-pattern)
- Windows Command Shell (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Tool (attack-pattern)
- Windows Service (attack-pattern)
- SMB/Windows Admin Shares (attack-pattern)
- Data Staged (attack-pattern)
- Domain Accounts (attack-pattern)
- Process Injection (attack-pattern)
- Remote Services (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Pass the Hash (attack-pattern)
- Windows Permissions (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Malicious File (attack-pattern)
- Scheduled Task (attack-pattern)
- Command Obfuscation (attack-pattern)
- File Deletion (attack-pattern)
- Group Policy Preferences (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Security Software Discovery (attack-pattern)
- Rundll32 (attack-pattern)
- Kerberoasting (attack-pattern)
Reports & references
- secureworks.com — How Cyber Adversaries Are Adapting To Exploit The Global Pandemic (report)
- CrowdStrike — Big Game Hunting With Ryuk Another Lucrative Targeted Ransomware (report)
- Mandiant — A Nasty Trick From Credential Theft Malware To Business Disruption (report)
- labs.sentinelone.com — Top Tier Russian Organized Cybercrime Group Unveils Fileless Stealthy Powertrick Backdoor For High Value Targets (report)
- CrowdStrike — Sin Ful Spiders Wizard Spider And Lunar Spider Sharing The Same Web (report)
- CrowdStrike — Wizard Spider Lunar Spider Shared Proxy Module (report)
- CrowdStrike — Wizard Spider Adds New Feature To Ryuk Ransomware (report)
- cybereason.com — Dropping Anchor From A Trickbot Infection To The Discovery Of The Anchor Malware (report)
- secureworks.com — Gold Ulrick (report)
- secureworks.com — Dyre Banking Trojan (report)
- secureworks.com — Trickbot Modifications Target Us Mobile Users (report)
- secureworks.com — Gold Blackburn (report)
- strapi.eurepoc.eu — Eu Repo C Apt Profile Conti Wizard Spider Dc2A733E18 (report)
- prodaft.com — Wizardspider Tlpwhite V.1.4 (report)
- securityintelligence.com — Itg23 Crypters Cooperation Between Cybercriminal Groups (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- Mandiant — Kegtap And Singlemalt With A Ransomware Chaser (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G0102 (report)
- securityintelligence.com — Trickbot Gang Doubles Down Enterprise Infection (report)
- CISA — Aa20 302A (report)
- web.archive.org — Fin12 Group Profile (report)
- CrowdStrike — Timelining Grim Spiders Big Game Hunting Tactics (report)
- CrowdStrike — Wizard Spider Adversary Update (report)
Attributed from
- FIN12 March 2023 Hospital Center Intrusion (campaign)
External references
- mitre-attack — G0102
- Grim Spider
- UNC1878
- TEMP.MixMaster
- ITG23
- FIN12
- Periwinkle Tempest
- DEV-0193
- Pistachio Tempest
- DEV-0237
- GOLD BLACKBURN
- DHS/CISA Ransomware Targeting Healthcare October 2020
- FireEye Ryuk and Trickbot January 2019
- CrowdStrike Ryuk January 2019
- CrowdStrike Grim Spider May 2019
- FireEye KEGTAP SINGLEMALT October 2020
- Microsoft Threat Actor Naming July 2023
- Microsoft_PistachioTempest_Jan2024
- CrowdStrike Wizard Spider October 2020
- Secureworks Gold Blackburn Mar 2022