Indrik Spider

MITRE ATT&CK: G0119 View on attack.mitre.org

Aliases: Evil Corp, Manatee Tempest, DEV-0243, UNC2165, Indrik Spider, EvilCorp

First seen
2014-01-01 00:00:00
Origin
RU
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Related IoCs
2
Last IoC activity
2026-07-31 05:16:51
Profile updated
2026-07-07 12:33:14

Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications

Targeted regions: country_code:us country_code:gb country_code:de

Context

Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.

Detection coverage

  • 166 YARA rules
  • 834 Sigma rules

Malware & tools used

  • Malware (attack-pattern)
  • Create Account (attack-pattern)
  • Modify Registry (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Acquire Infrastructure (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Password Managers (attack-pattern)
  • Gather Victim Network Information (attack-pattern)
  • PowerShell (attack-pattern)
  • Domain Accounts (attack-pattern)
  • Credentials In Files (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Group Policy Modification (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Local Account (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • JavaScript (attack-pattern)
  • Email Accounts (attack-pattern)

Related threat objects

Reports & references

  • CrowdStrike — Big Game Hunting The Evolution Of Indrik Spider From Dridex Wire Fraud To Bitpaymer Targeted Ransomware (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G0119 (report)
  • cloud.google.com — Unc2165 Shifts To Evade Sanctions (report)
  • home.treasury.gov — Sm845 (report)
  • CrowdStrike — Hades Ransomware Successor To Indrik Spiders Wastedlocker (report)

External references