Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Wizard Spider

Also known as: UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, DEV-0237, GOLD ULRICK, Storm-0193, Trickbot LLC, UNC2053, Storm-0230, the TrickBot Gang, Trickbot, tracked as, Ryuk Stealer, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Shathak, ALPHV, AlphaVM

Description

Wizard Spider is a sophisticated threat actor that has evolved from a purely ransomware distributor into a multi‑phase adversary capable of large‑scale espionage. Its attack lifecycle typically begins with spearphishing attachments or links, followed by the deployment of banking trojans such as TrickBot or Emotet to establish persistence and credential theft. Once foothold is achieved, the actor escalates privileges, moves laterally via SMB/CIFS shares and remote services, and eventually delivers its own ransomware payloads—primarily Conti and occasionally Diavol—to encrypt data for extortion. The group’s operations exhibit a modular tiered structure: initial access vectors include spearphishing, exploitation of edge devices, or compromised web hosts; execution leverages Windows native binaries (e.g., rundll32.exe), PowerShell scripts, and DLL injection; persistence is achieved through service creation, scheduled tasks, and registry run keys. Credential harvesting is accomplished with LSASS memory dumps or NTDS database extraction, while data exfiltration can occur via standard application layer protocols or covert cloud storage channels. Strategically, Wizard Spider pursues dual objectives—financial gain through ransomware payouts and information theft from high‑profile targets such as defense contractors, hospitals, and utilities. Operation tempo is brisk; campaigns may span weeks to months with periodic infrastructure hopping (e.g., transferring command & control servers to VPT or VOLTZITE). Notable incidents include the 2023 Onslow Water breach in North Carolina and a supply chain compromise through an MSP serving multiple U.S. newspapers.

TTP Summary

Onslow, North Carolina water; Dataresolution.net (MSP for multiple US newpapers)

Goals & Targeting

Targeted Sectors

Defense
Financial services
Government
Healthcare
Telecommunications
Manufacturing
Education
Non profit
Media
Critical infrastructure
Energy
Pharmaceutical
Aviation
Hospitality
Aerospace
Retail
Information technology
Think tank
Transportation
Mining
Chemical
Gaming
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

GB
US
CN
RU
IR
VN
JP
IL
AU
SA
PK
TW
DE
AE
UA
SG
KR
IN
CA
BY
TR
FR
MX
ES
PL
IT
RO
NG
KP
LB
AZ
KZ
NL

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 5 hours ago

Executive Summary

Wizard Spider is a Russian‑linked cybercrime unit that has operated since at least 2016, distributing the Conti and Diavol ransomware with TrickBot as its primary dropper. The group blends financially driven extortion via ransomware with parallel espionage operations against high‑value sectors worldwide. Recent campaigns demonstrate aggressive tactics—spearphishing, malware cascading through Emotet/IcedID, lateral movement across SMB shares, and exploitation of internet‑facing devices—to reach critical infrastructure and corporate enterprises.

Goals & Targeting

Wizard Spider’s primary goal is monetization through ransomware, yet it also engages in espionage against sectors where actionable intelligence yields strategic advantage. The actor targets an extensive list of industries—finance, healthcare, energy, defense, etc.—with a focus on organizations that house complex network environments and valuable data repositories. Geographic reach spans Europe, North America, Asia, and the Middle East, often exploiting multinational supply chains to widen impact.

Enhanced Description

Key Capabilities

  • Deploy Conti ransomware and its variants
  • Use TrickBot as a dropper payload
  • Initial access via spearphishing emails or links
  • Infection through Emotet or IcedID before dropping core malware
  • Toolset modification and expansion over time
  • Exploit internet‑facing edge devices for initial compromise
  • Transfer access to Volt Typhoon/VOLTZITE for follow‑on operations
  • Target major corporations and hospitals with ransomware attacks
  • Distribute BazarBackdoor alongside TrickBot in partnership with TA551 (Shathak)

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Credential Access
Collection
Exfiltration
Command and Control
Impact

ATT&CK Techniques

T1566.001
T1105
T1071
T1485
T1486
T1491
T1685
T1083
T1053.005
T1560.001
T1047
T1033
T1583
T1218.011
T1133
T1003.002
T1074.001
T1489
T1087.002
T1204.002
T1543.003
T1566.002
T1553.002
T1135
T1222.001
T1082
T1106
T1584.003
T1005
T1055
T1518.002
T1021.002
T1112
T1547.004
T1016
T1136.001
T1555.004
T1490
T1105
T1569.002
T1558.003
T1055.001
T1048.003

Software / Tooling

TrickBot
Emotet
IcedID
Conti
Diavol
BazarBackdoor
Volt Typhoon
VOLTZITE
SystemBC
Black Basta
Cobalt Strike
Dark
Ryuk
Hive

Campaigns & Victims

Wizard Spider exhibits a high‑frequency campaign cadence, launching attacks on multiple fronts with synchronized infrastructure hopping to obfuscate attribution. Victims are typically large enterprises or critical‑infrastructure entities that provide both financial liquidity and sensitive data streams. Past operations—such as the 2023 Onslow Water breach, the MSP Dataresolution.net supply‑chain compromise, and a multi‑country healthcare data exfiltration—demonstrate the actor’s ability to pivot across sectors, leverage compromised web services, and maintain long‑term persistence via tiered backdoors.

IOC Patterns

  • malicious email attachment
  • dropper malware vector
  • banking trojan payload
  • ransomware encryption activity
  • initial infection via Emotet or IcedID
  • domain-based command & control
  • file hash signature of rundll32.exe and mshta.exe

Recommended Actions

  • Enforce hardened email security—filtering, sandboxing, and user education to mitigate spearphishing attacks.
  • Deploy endpoint detection and response solutions capable of detecting TrickBot, Emotet, IcedID, Conti, and Diavol activities.
  • Monitor for ransomware‑specific behaviors such as rapid file encryption, unusual registry changes, or abnormal scheduled tasks.
  • Apply the principle of least privilege; disable unused services, enforce MFA, and conduct regular patching to protect SMB shares and remote services.
  • Block known malicious domains and IPs associated with TrickBot, Emotet, Volt Typhoon, and VOLTZITE via network firewall rules.

Suggested Tags

ransomware
financial crime
banking trojan
malicious email
dropper malware
Russian‑linked
Conti
Diavol
Trickbot
Wizard Spider
ITG23
TrickBot Gang
Shathak
TA551
Volt Typhoon
VOLTZITE
BazarBackdoor
SyLVANITE
Russia‑based financially motivated group

Confidence Assessment

The consolidated intelligence stems from multiple reputable sources, providing a high level of confidence in the actor’s primary capabilities and operational patterns. However, detailed infrastructure mappings and precise motivation (e.g., pure espionage vs. hybrid model) remain less well defined due to limited publicly available attribution evidence. Further monitoring of emerging IOC sets may refine threat context.

ATT&CK Techniques

Credential Access
7 techniques
Defense impairment
4 techniques
Discovery
11 techniques
Execution
8 techniques
Lateral Movement
7 techniques
Persistence
6 techniques
Resource Development
11 techniques
Stealth
10 techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. DHS/CISA Ransomware Targeting Healthcare October 2020 — DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.
  2. FireEye Ryuk and Trickbot January 2019 — Goody, K., et al (2019, January 11). A Nasty Trick: From Credential Theft Malware to Business Disruption. Retrieved May 12, 2020.
  3. CrowdStrike Ryuk January 2019 — Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.
  4. CrowdStrike Grim Spider May 2019 — John, E. and Carvey, H. (2019, May 30). Unraveling the Spiderweb: Timelining ATT&CK Artifacts Used by GRIM SPIDER. Retrieved May 12, 2020.
  5. FireEye KEGTAP SINGLEMALT October 2020 — Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.
  6. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  7. Microsoft_PistachioTempest_Jan2024 — Microsoft. (2024, January 25). Financially Motivated Threat Actor Pistachio Tempest. Retrieved December 15, 2025.
  8. CrowdStrike Wizard Spider October 2020 — Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021.
  9. Secureworks Gold Blackburn Mar 2022 — Secureworks Counter Threat Unit. (2022, March 1). Gold Blackburn Threat Profile. Retrieved June 15, 2023.
  10. Mandiant FIN12 Oct 2021 — Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.
  11. IBM X-Force ITG23 Oct 2021 — Villadsen, O., et al. (2021, October 13). Trickbot Rising - Gang Doubles Down on Infection Efforts to Amass Network Footholds. Retrieved June 15, 2023.
  12. attack.mitre.org — Cited by web research for: Sandworm Team
  13. www.cybereason.com — Cited by web research for: Shathak
  14. www.trendmicro.com — Cited by web research for: ALPHV
  15. docs.rapid7.com — Cited by web research for: T1583
  16. redcanary.com — Cited by web research for: T1571
  17. attack.mitre.org — Cited by web research for: T1071
  18. https://www.ibm.com/think/x-force/trickbot-gang-doubles-down-enterprise-infection — Cited by AI analysis.
  19. https://www.cybereason.com/blog/mitre-attck-wizard-spider-and-sandworm-evaluations-explained — Cited by AI analysis.
  20. https://www.akamai.com/glossary/what-is-conti-ransomware — Cited by AI analysis.
  21. https://www.huntress.com/threat-library/threat-actors/wizard-spider — Cited by AI analysis.
  22. https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-110a — Cited by AI analysis.
  23. https://www.crowdstrike.com/en-us/blog/wizard-spider-adversary-update/ — Cited by AI analysis.
  24. https://malpedia.caad.fkie.fraunhofer.de/actor/wizard_spider — Cited by AI analysis.
  25. https://malpedia.caad.fkie.fraunhofer.de/actor/unc1878 — Cited by AI analysis.

Intel Summary

82

Techniques

52

Tools

2

Campaigns

138

IOCs

0

Observed Data

13

Tactics

Tags

Ransomware
APT
Healthcare Targeting
Critical Infrastructure
Supply Chain Attack
ransomware
financial crime
banking trojan
malicious email
dropper malware
Russian‑linked
Conti
Diavol
Trickbot
Wizard Spider
ITG23
TrickBot Gang
Shathak
TA551
Volt Typhoon
VOLTZITE
BazarBackdoor
SyLVANITE
Russia‑based financially motivated group

Details

MITRE ID
G0102
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--dd2d9ca6-505b-4860-a604-233685b802c7
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.