Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BITWISE SPIDER

Also known as: other aliases, LockBit, several other aliases, UNC3944, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, Turbine Panda, Hippo Team, JerseyMikes, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, Cobalt Group, GOLD KINGSWOOD, COBALT SPIDER, G0080, Mule Libra, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, Magecart Group 4, T-APT-04, India, COLD RELIC, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Turla, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, the Newscaster Team, Syrphid, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, APT28, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig

Description

BITWISE SPIDER, also catalogued as UNC3944, Scattered Spider, and other monikers such as IndrikSpider or Buhti, is a state‑aligned ransomware gang that has been active since at least 2019. The operator orchestrates cyberattacks through a sophisticated RaaS framework, delivering malware via dedicated Download Link Servers (DLS) and exploiting PowerShell execution environments to spread rapidly within victim networks. Following early successes, BITWISE SPIDER refined its tactics into a classic triple‑extortion scheme: first encrypting corporate data with LockBit variants, then exfiltrating sensitive files over cloud storage or custom C2 channels, and finally threatening public release on leak sites if ransoms are unmet. This high‑pressure methodology has been leveraged against finance, healthcare, defense, energy and critical infrastructure customers worldwide. The gang’s operational toolkit is diverse: it uses memory‑only execution to evade detection, logs removal scripts, credential dumping via Mimikatz, lateral movement with CrackMapExec/PsExec, and phishing or spear‑phishing campaigns. Their supply‑chain approach targets third‑party web hosts for strategic web compromise (SWC), while RMM software exploitation serves as a vector to infect downstream clients. Law enforcement raids in 2024 disrupted infrastructure, yet BITWISE SPIDER adapted quickly, repurposing existing payloads and developing new variants such as LockBit RED. The group also shows signs of recruiting insiders, exploiting weak or compromised Azure Key Vault credentials, and using zero‑day vulnerabilities in Exchange and ESXi hosts to expand footholds.

TTP Summary

Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites

Goals & Targeting

Targeted Sectors

Financial services
Government
Healthcare
Defense
Telecommunications
Critical infrastructure
Manufacturing
Education
Media
Energy
Aviation
Transportation
Non profit
Legal services
Aerospace
Hospitality
Utilities
Think tank
Maritime
Gaming
Retail
Information technology
Aerospace & defense
Legal

Targeted Countries / Regions

MX
RU
US
CN
IR
BR
IN
KP
KR
TR
UA
VN
PK
CA

AI Analysis

Grounded in web research
· analyzed in 15 chunks · 3 days ago

Executive Summary

BITWISE SPIDER is a rapid‑moving ransomware‑as‑a‑service operator that primarily deploys LockBit variants, notably LockBit RED and 3.x, using a triple–extortion model involving encryption, data exfiltration and leak threats. The group aggressively targets high‑profile sectors across the Americas, Eurasia and Africa through big‑game hunting campaigns, supply‑chain compromises and remote monitoring tool infection vectors. Despite law‑enforcement disruption in 2024, BITWISE SPIDER continues to generate large volumes of stolen data, maintain updated encryptors and expand its affiliate network.

Goals & Targeting

The strategic objective of BITWISE SPIDER is predominantly financial gain, achieved through large ransom payments enabled by the triple‑extortion model. By focusing on high‑profile or high‑value targets—government agencies, critical infrastructure, and sectors with predictable budgets—the attacker maximizes revenue while minimizing resistance. The gang also seeks to extract market intelligence by exfiltrating data that could be leveraged for future influence operations or blackmail.

Enhanced Description

Key Capabilities

  • Deploys LockBit ransomware variants (LockBit RED, 3.x)
  • Employs triple‑extortion strategy (encryption + data exfiltration + leak threat)
  • Uses Download Link Servers for delivery
  • Executes payloads via PowerShell and Empire-style scripts
  • Targets high‑value victims through big‑game hunting campaigns
  • Performs in‑memory propagation and log deletion to evade detection
  • Conducts credential dumping using Mimikatz and lateral movement with CrackMapExec and PsExec
  • Launches phishing & spear‑phishing campaigns for initial access
  • Exploits unpatched software, zero‑day vulnerabilities and weak credentials
  • Targets Microsoft Exchange servers and ESXi hosts via exploitation
  • Leverages remote monitoring & management (RMM) tools to infect downstream clients
  • Operates a ransomware‑as‑a‑service model with affiliate recruitment and insider channels
  • Conducts supply‑chain attacks via compromised third‑party web services

MITRE ATT&CK Tactics

Execution
Exfiltration
Impact
Credential Access
Lateral Movement
Defense Evasion
Initial Access
Persistence
Privilege Escalation
Command and Control
Collection
Detection and Monitoring
Credential Acquisition

ATT&CK Techniques

T1059.001
T1486
T1003.001
T1218.004
T1075
T1566.001
T1078
T1021
T1041
T1068
T1543.003
T1566.002
T1110
T1404
T1566
T1105
T1190
T1074.3
T1071.001
T1048.004
T1555.003
T1113
T1528
T1059.003
T1487

Software / Tooling

LockBit
LockBit RED
PowerShell Empire
Download Link Servers (DLS)
LockBit 3.0
Indrik Spider
Buhti
Syrphid
StealBIT
Dridex
Kronos
Nanocore RAT
NJrat
3AM
CrackMapExec
EmpireProject
Mimikatz
PsExec
PrivateLoader
Defray777
IcedID
BokBot
Latrodectus
Lotus Loader
Cobalt Strike
Brute Ratel
SparrowDoor
AsyncRAT
DanaBot
KV-Botnet
Fenix botnet
Mispadu Stealer
Grandoreiro
Casabaneiro (Mekotio)
Chronus Team
Guacamaya
Mexicnon
adrxx

IOC Patterns

  • In‑memory execution
  • Removal of logs and supporting files
  • Phishing emails masquerading as copyright claim notices
  • Use of legitimate RMM tools for lateral infiltration
  • Public data leak sites used to expose stolen victim data
  • Triple‑extortion approach combining encryption, exfiltration, and release threats
  • Large volumes of leaked exfiltrated data reported
  • Theft of medical/employee data in ransom demands
  • Phishing attachments or links used for initial compromise
  • Exploitation of Microsoft Exchange servers via public‑facing application vulnerability
  • Malicious Word document attachment masquerading as a resume
  • Exploit unpatched vulnerabilities
  • Credential brute‑force attack
  • Targeted exploitation of virtualization platforms (ESXi) for ransomware deployment
  • Big game hunting attack pattern
  • Distribution of ransomware variants via advanced extortion channels
  • Banking trojan, downloader malware, loader families
  • Suspicious SQL injection payloads in web applications
  • Use of cloud storage URLs for data upload (Dropbox, Google Drive, OneDrive)
  • Exfiltration attempts via HTTP(S) to cloud services
  • Malware binaries and dropper files
  • Botnet C2 domain/IP addresses
  • RANSOMWARE ransom notes
  • Dark web forum references
  • Credential exposure incidents

Recommended Actions

  • Implement advanced email filtering and user training to detect phishing attempts
  • Enforce strict control, monitoring, and patching of remote monitoring & management tools; restrict privileged access
  • Maintain isolated, offline backups and test recovery procedures regularly
  • Deploy data loss prevention (DLP) solutions to block unauthorized data exfiltration
  • Block outbound connections to known or suspicious command‑and‑control domains associated with ransomware leak sites
  • Implement multi‑factor authentication (MFA) across all systems
  • Apply regular patch management to mitigate zero‑day and known vulnerabilities
  • Deploy endpoint detection & response (EDR) tools for malware signature and anomalous behavior detection
  • Enforce network segmentation standards to contain lateral movement
  • Patch and secure web application inputs to prevent SQL injection
  • Monitor and block outbound exfiltration traffic to cloud storage services
  • Detect and investigate large compressed file transfers, permission changes, screenshot captures
  • Block or closely monitor remote desktop sessions used for exfiltration
  • Enforce least‑privilege IAM policies and continuous monitoring of data transfer activities
  • Implement encryption for all exfiltration channels and block insecure protocols
  • Enhance incident response planning and conduct scenario‑planning exercises focusing on ransomware , data breaches, cyber espionage

Suggested Tags

ransomware
LockBit
BITWISE SPIDER
PowerShell
big game hunting
IndrikSpider
Buhti
Syrphid
Ransomware-as-a-Service
Double-Extortion
Financial-Gain-Motivation
Russia-affiliated
StealBIT
phishing
triple_extortion
insider_recruitment
affiliate_program
rmm_exploitation
data_leak
data-exfiltration
supply-chain-compromise
government-targeting
healthcare‑targeting
financial-sector
critical-infrastructure
education
media
energy
aerospace-and-defense
telecommunications
manufacturing
non-profit

Confidence Assessment

The analysis is based on a wide range of publicly available sources, including technical reports, vendor threat feeds and incident write‑ups. While the core facts—such as LockBit variant use, triple‑extortion tactics, big‑game hunting focus, and supply‑chain compromise methods—are consistently reported, attribution remains probabilistic and some operational details (exact infrastructure, full scope of affiliate network, internal budgeting) are still incomplete. Confidence is moderate to high for known capabilities and targeting; gaps persist around precise timelines post‑law enforcement disruption and potential re‑emergence under new aliases.

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 Filename 9

References

  1. www.huntress.com — Cited by web research for: other aliases
  2. apt.etda.or.th — Cited by web research for: phishing
  3. www.huntress.com — Cited by web research for: STOP
  4. www.crowdstrike.com — Cited by web research for: CVE-2026-20929
  5. www.recordedfuture.com — Cited by web research for: Information Technology

Intel Summary

25

Techniques

89

Tools

7

Campaigns

39

IOCs

0

Observed Data

12

Tactics

Tags

Ransomware
BGH
Healthcare Sector Targeting
Educational Institutions Targeting
LockBit-related
Data Exfiltration
Extortion
ransomware
LockBit
BITWISE SPIDER
PowerShell
big game hunting
IndrikSpider
Buhti
Syrphid
Ransomware-as-a-Service
Double-Extortion
Financial-Gain-Motivation
Russia-affiliated
StealBIT
phishing
triple_extortion
insider_recruitment
affiliate_program
rmm_exploitation
data_leak
data-exfiltration
supply-chain-compromise
government-targeting
healthcare‑targeting
financial-sector
critical-infrastructure
education
media
energy
aerospace-and-defense
telecommunications
manufacturing
non-profit

Details

MITRE ID
APT26
Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.