Also known as: UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, DEV-0237, GOLD ULRICK, Storm-0193, Trickbot LLC, UNC2053, Storm-0230, the TrickBot Gang, Trickbot, tracked as, Ryuk Stealer, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Shathak, ALPHV, AlphaVM
Wizard Spider is a sophisticated threat actor that has evolved from a purely ransomware distributor into a multi‑phase adversary capable of large‑scale espionage. Its attack lifecycle typically begins with spearphishing attachments or links, followed by the deployment of banking trojans such as TrickBot or Emotet to establish persistence and credential theft. Once foothold is achieved, the actor escalates privileges, moves laterally via SMB/CIFS shares and remote services, and eventually delivers its own ransomware payloads—primarily Conti and occasionally Diavol—to encrypt data for extortion. The group’s operations exhibit a modular tiered structure: initial access vectors include spearphishing, exploitation of edge devices, or compromised web hosts; execution leverages Windows native binaries (e.g., rundll32.exe), PowerShell scripts, and DLL injection; persistence is achieved through service creation, scheduled tasks, and registry run keys. Credential harvesting is accomplished with LSASS memory dumps or NTDS database extraction, while data exfiltration can occur via standard application layer protocols or covert cloud storage channels. Strategically, Wizard Spider pursues dual objectives—financial gain through ransomware payouts and information theft from high‑profile targets such as defense contractors, hospitals, and utilities. Operation tempo is brisk; campaigns may span weeks to months with periodic infrastructure hopping (e.g., transferring command & control servers to VPT or VOLTZITE). Notable incidents include the 2023 Onslow Water breach in North Carolina and a supply chain compromise through an MSP serving multiple U.S. newspapers.
Onslow, North Carolina water; Dataresolution.net (MSP for multiple US newpapers)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Wizard Spider is a Russian‑linked cybercrime unit that has operated since at least 2016, distributing the Conti and Diavol ransomware with TrickBot as its primary dropper. The group blends financially driven extortion via ransomware with parallel espionage operations against high‑value sectors worldwide. Recent campaigns demonstrate aggressive tactics—spearphishing, malware cascading through Emotet/IcedID, lateral movement across SMB shares, and exploitation of internet‑facing devices—to reach critical infrastructure and corporate enterprises.
Goals & Targeting
Wizard Spider’s primary goal is monetization through ransomware, yet it also engages in espionage against sectors where actionable intelligence yields strategic advantage. The actor targets an extensive list of industries—finance, healthcare, energy, defense, etc.—with a focus on organizations that house complex network environments and valuable data repositories. Geographic reach spans Europe, North America, Asia, and the Middle East, often exploiting multinational supply chains to widen impact.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Wizard Spider exhibits a high‑frequency campaign cadence, launching attacks on multiple fronts with synchronized infrastructure hopping to obfuscate attribution. Victims are typically large enterprises or critical‑infrastructure entities that provide both financial liquidity and sensitive data streams. Past operations—such as the 2023 Onslow Water breach, the MSP Dataresolution.net supply‑chain compromise, and a multi‑country healthcare data exfiltration—demonstrate the actor’s ability to pivot across sectors, leverage compromised web services, and maintain long‑term persistence via tiered backdoors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The consolidated intelligence stems from multiple reputable sources, providing a high level of confidence in the actor’s primary capabilities and operational patterns. However, detailed infrastructure mappings and precise motivation (e.g., pure espionage vs. hybrid model) remain less well defined due to limited publicly available attribution evidence. Further monitoring of emerging IOC sets may refine threat context.
Onslow, North Carolina water
No observed data linked yet.
82
Techniques
52
Tools
2
Campaigns
138
IOCs
0
Observed Data
13
Tactics