INDRIK SPIDER
MISPUnknown
RU
Unknown
[Indrik Spider](https://attack.mitre.org/groups/G0119) is a Russia-based cybercriminal group that has been active since at least 2014. [Indrik Spider](https://attack.mitre.org/groups/G0119) initially started with the [Dridex](https://attack.mitre.org/software/S0384) banking Trojan, and then by 2017 they began running ransomware operations using [BitPaymer](https://attack.mitre.org/software/S0570), [WastedLocker](https://attack.mitre.org/software/S0612), and Hades ransomware. Following U.S. sanctions and an indictment in 2019, [Indrik Spider](https://attack.mitre.org/groups/G0119) changed their tactics and diversified their toolset.(Citation: Crowdstrike Indrik November 2018)(Citation: Crowdstrike EvilCorp March 2021)(Citation: Treasury EvilCorp Dec 2019)
Tecniche Utilizzate (33)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1003.001 | LSASS Memory | - |
| T1007 | System Service Discovery | - |
| T1012 | Query Registry | - |
| T1018 | Remote System Discovery | - |
| T1021.001 | Remote Desktop Protocol | - |
| T1021.004 | SSH | - |
| T1036.005 | Match Legitimate Resource Name or Location | - |
| T1047 | Windows Management Instrumentation | - |
| T1059.001 | PowerShell | - |
| T1059.003 | Windows Command Shell | - |
| T1059.007 | JavaScript | - |
| T1070.001 | Clear Windows Event Logs | - |
| T1074.001 | Local Data Staging | - |
| T1078 | Valid Accounts | - |
| T1078.002 | Domain Accounts | - |
Alias (980)
Malware Utilizzato (8)
Metadata
| ID: | 192 |
| Created: | 13/01/2026 17:48 |
| Updated: | 21/04/2026 16:00 |