G0102

G0102Wizard Spider

Description

[Wizard Spider](https://attack.mitre.org/groups/G0102) is a Russia-based financially motivated threat group originally known for the creation and deployment of [TrickBot](https://attack.mitre.org/software/S0266) since at least 2016. [Wizard Spider](https://attack.mitre.org/groups/G0102) possesses a diverse aresenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.(Citation: CrowdStrike Ryuk January 2019)(Citation: DHS/CISA Ransomware Targeting Healthcare October 2020)(Citation: CrowdStrike Wizard Spider October 2020)

References

  1. https://attack.mitre.org/groups/G0102
  2. https://us-cert.cisa.gov/ncas/alerts/aa20-302a
  3. https://www.fireeye.com/blog/threat-research/2019/01/a-nasty-trick-from-credential-theft-malware-to-business-disruption.html
  4. https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/
  5. https://www.crowdstrike.com/blog/timelining-grim-spiders-big-game-hunting-tactics/
  6. https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html
  7. https://www.crowdstrike.com/blog/wizard-spider-adversary-update/
  8. https://www.secureworks.com/research/threat-profiles/gold-blackburn
  9. https://www.mandiant.com/sites/default/files/2021-10/fin12-group-profile.pdf
  10. https://securityintelligence.com/posts/trickbot-gang-doubles-down-enterprise-infection/

Software attributed to this2

TypeTargetConfidenceTier
SoftwareTrickBots0266100%live
SoftwareDiavols0659100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
Indrik Spider
Software
TrickBot
Actor
GRIM SPIDER
Group
Scattered Spider
Group
EXOTIC LILY
Actor
GURU SPIDER
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.