Also known as: other aliases, LockBit, several other aliases, UNC3944, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, Turbine Panda, Hippo Team, JerseyMikes, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, Cobalt Group, GOLD KINGSWOOD, COBALT SPIDER, G0080, Mule Libra, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, Magecart Group 4, T-APT-04, India, COLD RELIC, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Turla, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, the Newscaster Team, Syrphid, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig
BITWISE SPIDER, also catalogued as UNC3944, Scattered Spider, and other monikers such as IndrikSpider or Buhti, is a state‑aligned ransomware gang that has been active since at least 2019. The operator orchestrates cyberattacks through a sophisticated RaaS framework, delivering malware via dedicated Download Link Servers (DLS) and exploiting PowerShell execution environments to spread rapidly within victim networks. Following early successes, BITWISE SPIDER refined its tactics into a classic triple‑extortion scheme: first encrypting corporate data with LockBit variants, then exfiltrating sensitive files over cloud storage or custom C2 channels, and finally threatening public release on leak sites if ransoms are unmet. This high‑pressure methodology has been leveraged against finance, healthcare, defense, energy and critical infrastructure customers worldwide. The gang’s operational toolkit is diverse: it uses memory‑only execution to evade detection, logs removal scripts, credential dumping via Mimikatz, lateral movement with CrackMapExec/PsExec, and phishing or spear‑phishing campaigns. Their supply‑chain approach targets third‑party web hosts for strategic web compromise (SWC), while RMM software exploitation serves as a vector to infect downstream clients. Law enforcement raids in 2024 disrupted infrastructure, yet BITWISE SPIDER adapted quickly, repurposing existing payloads and developing new variants such as LockBit RED. The group also shows signs of recruiting insiders, exploiting weak or compromised Azure Key Vault credentials, and using zero‑day vulnerabilities in Exchange and ESXi hosts to expand footholds.
Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites
Targeted Sectors
Targeted Countries / Regions
Executive Summary
BITWISE SPIDER is a rapid‑moving ransomware‑as‑a‑service operator that primarily deploys LockBit variants, notably LockBit RED and 3.x, using a triple–extortion model involving encryption, data exfiltration and leak threats. The group aggressively targets high‑profile sectors across the Americas, Eurasia and Africa through big‑game hunting campaigns, supply‑chain compromises and remote monitoring tool infection vectors. Despite law‑enforcement disruption in 2024, BITWISE SPIDER continues to generate large volumes of stolen data, maintain updated encryptors and expand its affiliate network.
Goals & Targeting
The strategic objective of BITWISE SPIDER is predominantly financial gain, achieved through large ransom payments enabled by the triple‑extortion model. By focusing on high‑profile or high‑value targets—government agencies, critical infrastructure, and sectors with predictable budgets—the attacker maximizes revenue while minimizing resistance. The gang also seeks to extract market intelligence by exfiltrating data that could be leveraged for future influence operations or blackmail.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on a wide range of publicly available sources, including technical reports, vendor threat feeds and incident write‑ups. While the core facts—such as LockBit variant use, triple‑extortion tactics, big‑game hunting focus, and supply‑chain compromise methods—are consistently reported, attribution remains probabilistic and some operational details (exact infrastructure, full scope of affiliate network, internal budgeting) are still incomplete. Confidence is moderate to high for known capabilities and targeting; gaps persist around precise timelines post‑law enforcement disruption and potential re‑emergence under new aliases.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
25
Techniques
89
Tools
7
Campaigns
39
IOCs
0
Observed Data
12
Tactics