Indrik Spider
MITRE ATT&CK: G0119 View on attack.mitre.org
Aliases: Evil Corp, Manatee Tempest, DEV-0243, UNC2165, Indrik Spider, EvilCorp
- First seen
- 2014-01-01 00:00:00
- Origin
- RU
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Related IoCs
- 2
- Last IoC activity
- 2026-07-31 05:16:51
- Profile updated
- 2026-07-07 12:33:14
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality technology-and-telecommunications
Targeted regions: country_code:us country_code:gb country_code:de
Context
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.
Detection coverage
- 166 YARA rules
- 834 Sigma rules
Malware & tools used
- Malware (attack-pattern)
- Create Account (attack-pattern)
- Modify Registry (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- System Service Discovery (attack-pattern)
- Acquire Infrastructure (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Local Data Staging (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Password Managers (attack-pattern)
- Gather Victim Network Information (attack-pattern)
- PowerShell (attack-pattern)
- Domain Accounts (attack-pattern)
- Credentials In Files (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Windows Command Shell (attack-pattern)
- Group Policy Modification (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Valid Accounts (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Local Account (attack-pattern)
- Remote System Discovery (attack-pattern)
- JavaScript (attack-pattern)
- Email Accounts (attack-pattern)
Related threat objects
- Mustard Tempest (threat-actor)
Reports & references
- CrowdStrike — Big Game Hunting The Evolution Of Indrik Spider From Dridex Wire Fraud To Bitpaymer Targeted Ransomware (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G0119 (report)
- cloud.google.com — Unc2165 Shifts To Evade Sanctions (report)
- home.treasury.gov — Sm845 (report)
- CrowdStrike — Hades Ransomware Successor To Indrik Spiders Wastedlocker (report)