Indrik Spider
Aliases: Evil Corp, Manatee Tempest, DEV-0243, UNC2165
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.
Open interactive actor investigation
ATT&CK techniques
T1003.001
LSASS MemoryT1587.001
MalwareT1136
Create AccountT1112
Modify RegistryT1036.005
Match Legitimate Name or LocationT1007
System Service DiscoveryT1583
Acquire InfrastructureT1070.001
Clear Windows Event LogsT1562.001
Disable or Modify ToolsT1074.001
Local Data StagingT1021.001
Remote Desktop ProtocolT1555.005
Password ManagersT1590
Gather Victim Network InformationT1059.001
PowerShellT1078.002
Domain AccountsT1552.001
Credentials In FilesT1567.002
Exfiltration to Cloud StorageT1059.003
Windows Command ShellT1484.001
Group Policy ModificationT1047
Windows Management InstrumentationT1078
Valid AccountsT1486
Data Encrypted for ImpactT1136.001
Local AccountT1018
Remote System DiscoveryT1059.007
JavaScriptT1585.002
Email AccountsT1105
Ingress Tool TransferT1489
Service StopT1012
Query RegistryT1558.003
KerberoastingT1204.002
Malicious FileT1021.004
SSHT1584.004
Server
LSASS MemoryT1587.001
MalwareT1136
Create AccountT1112
Modify RegistryT1036.005
Match Legitimate Name or LocationT1007
System Service DiscoveryT1583
Acquire InfrastructureT1070.001
Clear Windows Event LogsT1562.001
Disable or Modify ToolsT1074.001
Local Data StagingT1021.001
Remote Desktop ProtocolT1555.005
Password ManagersT1590
Gather Victim Network InformationT1059.001
PowerShellT1078.002
Domain AccountsT1552.001
Credentials In FilesT1567.002
Exfiltration to Cloud StorageT1059.003
Windows Command ShellT1484.001
Group Policy ModificationT1047
Windows Management InstrumentationT1078
Valid AccountsT1486
Data Encrypted for ImpactT1136.001
Local AccountT1018
Remote System DiscoveryT1059.007
JavaScriptT1585.002
Email AccountsT1105
Ingress Tool TransferT1489
Service StopT1012
Query RegistryT1558.003
KerberoastingT1204.002
Malicious FileT1021.004
SSHT1584.004
Server