Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Indrik Spider

Also known as: Evil Corp, Manatee Tempest, DEV-0243, UNC2165, GOLD DRAKE, other aliases, several other aliases, APT28, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Dridex, is a prolific, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Stately Tarurus, Chanitor, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, Sparkling Pisces, HIDDEN COBRA, ZINC, Labyrinth Chollima, Guardians of Peace, Mailto, Circus Spider, APT33, Royal, BlackSuit, UNC3944, Starfraud, Muddled Libra

Description

Indrik Spider is a multifaceted eCrime organization that first emerged in the mid‑2014 Dridex banking trojan era before branching into high‑impact ransomware operations. Originating from Russia, it leveraged spear‑phishing attachments and compromised web portals to harvest credentials and deploy malware across corporate networks. By 2017 the group introduced BitPaymer ransomware, which famously targeted the UK National Health Service; this code combined rudimentary encryption with defensive tactics such as process injection, self‑deletion and anti‑sandbox checks. In response to U.S. sanctions and a 2019 indictment, Indrik Spider diversified its toolkit by replacing BitPaymer with newer ransomware families—WastedLocker and Hades—to circumvent detection and broaden distribution vectors. The actors now employ social engineering via malicious emails, compromised legitimate sites, and credential‑based lateral movement. Commercial exploitation frameworks and bespoke post‑exploitation payloads, notably Cobalt Strike, underpin resilient command‑and‑control channels and persistent access. Operationally, the group demonstrates high adaptability, altering tactics under geopolitical pressure, expanding its malware portfolio, and maintaining an extensive alias network (Evil Corp, UNC2165, etc.) that complicates attribution. While financially motivated, Indrik Spider occasionally pursues espionage objectives, using stolen credentials to infiltrate sensitive government systems. Indrik Spider’s modular ecosystem re‑uses components across Dridex, ransomware kits, and shared hosting infrastructure for dropper binaries and key distribution. This code reuse strategy hinders straightforward detection yet exposes multiple attack surface points where security teams can intervene.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Critical infrastructure
Education
Manufacturing
Media
Energy
Non profit
Hospitality
Aviation
Aerospace
Retail
Pharmaceutical
Information technology
Think tank
Gaming
Transportation
Oil gas
Legal services
Mining
Chemical
Maritime
Utilities
Nuclear
Entertainment
Construction

Targeted Countries / Regions

CN
US
RU
IR
UA
VN
IN
JP
PK
TW
AU
IL
GB
KR
SA
AE
KP
SG
BY
BR
ES
DE
TR
MX
PL
CA
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

Indrik Spider (aka Evil Corp) is a Russia‑based cyber‑criminal collective that evolved from banking trojan operations to sophisticated ransomware and espionage campaigns. By exploiting spear‑phishing, compromised portals, and credential theft, the group delivers malware such as Dridex, BitPaymer, Hades, and WastedLocker, while leveraging commercial tools like Cobalt Strike for post‑exploitation persistence. Their attacks span government, finance, defense, healthcare and other critical sectors worldwide, achieving both financial ransom payouts and clandestine data exfiltration.

Goals & Targeting

The actors target high‑value sectors—government, finance, defense, healthcare, energy, telecoms—to maximize both monetary ransom payments and the acquisition of sensitive data for espionage or leverage. They focus on countries with strategic geopolitical relevance: Russia, United States, China, Iran, Ukraine, India, Japan, South Korea, and Middle Eastern states. By compromising critical infrastructures and high‑profile organizations, Indrik Spider seeks to secure large payouts while occasionally extracting actionable intelligence; typical victims include national health services, defense contractors, financial institutions, and multinational corporations with complex network perimeters.

Enhanced Description

Key Capabilities

  • Spear‑phishing attachments & malicious emails
  • Compromised legitimate web portals (dropper distribution)
  • Credential theft via banking trojans and password managers
  • Ransomware development (Dridex, BitPaymer, WastedLocker, Hades)
  • Use of commercial exploitation frameworks such as Cobalt Strike for persistence
  • Custom post‑exploitation RATs and DLL injection
  • Anti‑analysis tricks (sandbox detection, self‑deletion)
  • Infrastructure acquisition (bulletproof hosting, fast‑flux domains)
  • Credential‐based lateral movement via RDP, SSH, Kerberoasting
  • Data exfiltration to cloud storage or steganographic channels

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1059.007
T1074.001
T1036.005
T1489
T1583
T1204.002
T1021.004
T1555.005
T1007
T1106
T1112
T1484.001
T1136.001
T1685.005
T1552.001
T1059.001
T1590
T1078
T1486
T1218.010
T1511?
T1064?
T1086?
T1574.001

Software / Tooling

Dridex
BitPaymer
WastedLocker
Hades
Cobalt Strike
Malware
Custom RATs

Campaigns & Victims

Indrik Spider conducts its campaigns through a blend of spear‑phishing, web portal drops and credential‑based compromise. They operate on an adaptive schedule—launching new ransomware variants in response to sanctions or law‑enforcement pressure—and shift between direct delivery (email) and affiliate distribution via compromised sites. Victim profiles skew toward financially valuable enterprises (banking, health, defense) but also include government institutions for espionage. Their notable past operations include the 2017 NHS BitPaymer ransomware attack and various nationwide banking trojan infections in Southeast Asia.

IOC Patterns

  • Spear‑phishing attachments with macro‑laden Office documents
  • Malicious emails containing compressed dropper binaries
  • Compromised legitimate websites hosting Dridex or ransomware payloads
  • Use of commercial exploitation frameworks (Cobalt Strike) for persistence
  • Exfiltration via cloud services or covert protocols like SSH/TCP

Recommended Actions

  • Implement advanced email filtering and macro sandboxing to block spear‑phishing attachments; use threat intelligence feeds for known malicious hashes. Maintain rigorous patch management, especially on web servers and SMB clients, to limit exploitation of known vulnerabilities. Segment networks to isolate critical subnets, restricting lateral movement via RDP/SSH. Deploy host‑based EDR to detect process injection, registry tampering, and anomalous PowerShell execution. Enable detailed logging (registry, services, LSASS memory dumps) and monitor for event log clearing or service stoppage. Enforce least privilege and MFA on all privileged accounts; disable local admin rights where possible. Create out‑of‑band backups and test rapid recovery to mitigate data‑encryption impact. Conduct regular security awareness training focused on phishing recognition.

Suggested Tags

APT
ransomware
banking trojan
espionage
criminal
Russia-based
financial fraud
data encryption
critical infrastructure

Confidence Assessment

The intelligence is largely corroborated by reputable sources such as Malpedia and Red Canary, providing detailed attribution to Dridex, BitPaymer, and the group’s evolution. However, alias proliferation, dated operational reports, and overlapping actor naming (e.g., Evil Corp vs. Indrik Spider) introduce ambiguity. Further corroboration via up‑to‑date threat feeds is recommended for definitive attribution and campaign timelines.

ATT&CK Techniques

Defense impairment
4 techniques
Execution
7 techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. Crowdstrike Indrik November 2018 — Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.
  2. Mandiant_UNC2165 — Mandiant Intelligence. (2022, June 2). To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions. Retrieved July 29, 2024.
  3. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  4. Crowdstrike EvilCorp March 2021 — Podlosky, A., Feeley, B. (2021, March 17). INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions. Retrieved September 15, 2021.
  5. Treasury EvilCorp Dec 2019 — U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.
  6. www.huntress.com — Cited by web research for: other aliases
  7. attack.mitre.org — Cited by web research for: APT28
  8. redcanary.com — Cited by web research for: T1053.005
  9. apt.etda.or.th — Cited by web research for: Cobalt
  10. attack.mitre.org — Cited by web research for: STOP
  11. https://malpedia.caad.fkie.fraunhofer.de/actor/indrik_spider — Cited by AI analysis.

Intel Summary

40

Techniques

52

Tools

1

Campaigns

65

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
APT
Financial Targeting
Critical Infrastructure
Banking Trojan
Advanced Persistent Threat (APT)
Global Targeting
ransomware
banking trojan
espionage
criminal
Russia-based
financial fraud
data encryption
critical infrastructure

Details

MITRE ID
G0119
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--01e28736-2ffc-455b-9880-ed4d1407ae07
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.