G0102 · 67 ATT&CK techniques · 0 correlated reports

Wizard Spider

Aliases: UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse aresenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.

Open interactive actor investigation

ATT&CK techniques

T1136.001
Local Account
T1588.003
Code Signing Certificates
T1210
Exploitation of Remote Services
T1560.001
Archive via Utility
T1059.003
Windows Command Shell
T1047
Windows Management Instrumentation
T1588.002
Tool
T1543.003
Windows Service
T1021.002
SMB/Windows Admin Shares
T1074
Data Staged
T1078.002
Domain Accounts
T1055
Process Injection
T1021
Remote Services
T1021.001
Remote Desktop Protocol
T1550.002
Pass the Hash
T1222.001
Windows File and Directory Permissions Modification
T1570
Lateral Tool Transfer
T1204.002
Malicious File
T1053.005
Scheduled Task
T1027.010
Command Obfuscation
T1070.004
File Deletion
T1552.006
Group Policy Preferences
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
T1518.001
Security Software Discovery
T1218.011
Rundll32
T1558.003
Kerberoasting
T1059.001
PowerShell
T1567.002
Exfiltration to Cloud Storage
T1112
Modify Registry
T1490
Inhibit System Recovery
T1133
External Remote Services
T1547.004
Winlogon Helper DLL
T1036.004
Masquerade Task or Service
T1087.002
Domain Account
T1518
Software Discovery
T1071.001
Web Protocols
T1553.002
Code Signing
T1136.002
Domain Account
T1074.001
Local Data Staging
T1557.001
LLMNR/NBT-NS Poisoning and SMB Relay
T1105
Ingress Tool Transfer
T1003.003
NTDS
T1016
System Network Configuration Discovery
T1585.002
Email Accounts
T1033
System Owner/User Discovery
T1078
Valid Accounts
T1204.001
Malicious Link
T1003.001
LSASS Memory
T1041
Exfiltration Over C2 Channel
T1566.001
Spearphishing Attachment
T1003.002
Security Account Manager
T1489
Service Stop
T1566.002
Spearphishing Link
T1562.001
Disable or Modify Tools
T1018
Remote System Discovery
T1005
Data from Local System
T1082
System Information Discovery
T1555.004
Windows Credential Manager
T1135
Network Share Discovery
T1569.002
Service Execution
T1547.001
Registry Run Keys / Startup Folder
T1021.006
Windows Remote Management
T1055.001
Dynamic-link Library Injection
T1197
BITS Jobs
T1069.002
Domain Groups
T1482
Domain Trust Discovery
T1090
Proxy

Correlated CTI and IR reports

Continue the investigation