Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors RIDDLE SPIDER

Description

According to Crowdstrike, RIDDLE SPIDER is the operator behind the avaddon ransomware

AI Analysis

· 1 week ago

Executive Summary

RIDDLE SPIDER is a threat actor associated with the Avaddon ransomware family, which employs double extortion tactics. The group primarily targets healthcare, education, and other sectors globally, leveraging sophisticated techniques to breach organizations and encrypt sensitive data for financial gain.

Goals & Targeting

RIDDLE SPIDER's strategic objectives are centered around financial gain through ransomware deployments. The group primarily targets sectors with high data sensitivity and recovery costs, such as healthcare and education, where the impact of disruptions can be severe. RIDDLE SPIDER's global reach suggests a focus on broad geographic targeting to maximize victim pools.

Enhanced Description

RIDDLE SPIDER operates as a high-sophistication cybercriminal group responsible for deploying the Avaddon ransomware. This actor is known for its ability to disrupt operations by encrypting critical systems and demanding substantial ransoms, often threatening to release stolen data unless paid. The group's activities demonstrate a clear focus on maximizing financial gain through targeted ransom campaigns. RIDDLE SPIDER's operations highlight the evolving nature of ransomware attacks, where threat actors increasingly adopt professionalized tactics and tools to breach defenses and extort victims.

Key Capabilities

  • Ransomware deployment (Avaddon)
  • Double extortion tactics
  • Spear-phishing campaigns
  • Exploitation of remote desktop services (T5001)
  • Lateral movement within networks
  • Data encryption for disruption and extortion

MITRE ATT&CK Tactics

Initial Access
Execution
Impact

ATT&CK Techniques

T1566.001
T1485
T5001
T1078.001

Software / Tooling

Avaddon Ransomware
Cobalt Strike (potential usage)
Mimikatz
Trickbot/Qbot (potential for initial access)

Campaigns & Victims

RIDDLE SPIDER's campaigns demonstrate a focus on sectors with high recovery costs and data sensitivity. The group has been observed targeting healthcare organizations globally, causing significant disruptions. Notable operations include large-scale ransomware deployments that have resulted in data leaks and financial losses for victims. Campaign patterns indicate a preference for double extortion tactics, where encrypted data is also exfiltrated and released unless ransoms are paid.

IOC Patterns

  • Ransomware encryption patterns matching Avaddon
  • Creation of new user accounts with high privileges
  • External communication channels for ransom negotiations
  • Lateral movement via RDP or WMI
  • Encrypting backup files and systems

Recommended Actions

  • Implement robust patch management to address remote desktop service vulnerabilities (T5001)
  • Deploy endpoint detection and response (EDR) solutions to monitor for Cobalt Strike and Mimikatz activity
  • Conduct user training on phishing awareness to mitigate potential spear-phishing attempts
  • Encrypt backups and ensure they are air-gapped from the network
  • Monitor for unusual lateral movement activities within the network

Suggested Tags

Ransomware
Double extortion
Sector-specific targeting
Healthcare sector
Education sector
Global threat actor

Confidence Assessment

Confidence in RIDDLE SPIDER's TTPs and capabilities is high due to the detailed analysis of Avaddon ransomware campaigns by CrowdStrike. However, gaps exist regarding specific toolsets beyond Avaddon and exact targeting patterns outside healthcare.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Double extortion
Sector-specific targeting
Healthcare sector
Education sector
Global threat actor

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.