Also known as: Evil Corp, Manatee Tempest, DEV-0243, UNC2165, GOLD DRAKE, other aliases, several other aliases, APT28, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Dridex, is a prolific, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Stately Tarurus, Chanitor, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, Sparkling Pisces, HIDDEN COBRA, ZINC, Labyrinth Chollima, Guardians of Peace, Mailto, Circus Spider, APT33, Royal, BlackSuit, UNC3944, Starfraud, Muddled Libra
Indrik Spider is a multifaceted eCrime organization that first emerged in the mid‑2014 Dridex banking trojan era before branching into high‑impact ransomware operations. Originating from Russia, it leveraged spear‑phishing attachments and compromised web portals to harvest credentials and deploy malware across corporate networks. By 2017 the group introduced BitPaymer ransomware, which famously targeted the UK National Health Service; this code combined rudimentary encryption with defensive tactics such as process injection, self‑deletion and anti‑sandbox checks. In response to U.S. sanctions and a 2019 indictment, Indrik Spider diversified its toolkit by replacing BitPaymer with newer ransomware families—WastedLocker and Hades—to circumvent detection and broaden distribution vectors. The actors now employ social engineering via malicious emails, compromised legitimate sites, and credential‑based lateral movement. Commercial exploitation frameworks and bespoke post‑exploitation payloads, notably Cobalt Strike, underpin resilient command‑and‑control channels and persistent access. Operationally, the group demonstrates high adaptability, altering tactics under geopolitical pressure, expanding its malware portfolio, and maintaining an extensive alias network (Evil Corp, UNC2165, etc.) that complicates attribution. While financially motivated, Indrik Spider occasionally pursues espionage objectives, using stolen credentials to infiltrate sensitive government systems. Indrik Spider’s modular ecosystem re‑uses components across Dridex, ransomware kits, and shared hosting infrastructure for dropper binaries and key distribution. This code reuse strategy hinders straightforward detection yet exposes multiple attack surface points where security teams can intervene.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Indrik Spider (aka Evil Corp) is a Russia‑based cyber‑criminal collective that evolved from banking trojan operations to sophisticated ransomware and espionage campaigns. By exploiting spear‑phishing, compromised portals, and credential theft, the group delivers malware such as Dridex, BitPaymer, Hades, and WastedLocker, while leveraging commercial tools like Cobalt Strike for post‑exploitation persistence. Their attacks span government, finance, defense, healthcare and other critical sectors worldwide, achieving both financial ransom payouts and clandestine data exfiltration.
Goals & Targeting
The actors target high‑value sectors—government, finance, defense, healthcare, energy, telecoms—to maximize both monetary ransom payments and the acquisition of sensitive data for espionage or leverage. They focus on countries with strategic geopolitical relevance: Russia, United States, China, Iran, Ukraine, India, Japan, South Korea, and Middle Eastern states. By compromising critical infrastructures and high‑profile organizations, Indrik Spider seeks to secure large payouts while occasionally extracting actionable intelligence; typical victims include national health services, defense contractors, financial institutions, and multinational corporations with complex network perimeters.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Indrik Spider conducts its campaigns through a blend of spear‑phishing, web portal drops and credential‑based compromise. They operate on an adaptive schedule—launching new ransomware variants in response to sanctions or law‑enforcement pressure—and shift between direct delivery (email) and affiliate distribution via compromised sites. Victim profiles skew toward financially valuable enterprises (banking, health, defense) but also include government institutions for espionage. Their notable past operations include the 2017 NHS BitPaymer ransomware attack and various nationwide banking trojan infections in Southeast Asia.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is largely corroborated by reputable sources such as Malpedia and Red Canary, providing detailed attribution to Dridex, BitPaymer, and the group’s evolution. However, alias proliferation, dated operational reports, and overlapping actor naming (e.g., Evil Corp vs. Indrik Spider) introduce ambiguity. Further corroboration via up‑to‑date threat feeds is recommended for definitive attribution and campaign timelines.
No observed data linked yet.
40
Techniques
52
Tools
1
Campaigns
65
IOCs
0
Observed Data
14
Tactics