WIZARD SPIDER
MISPNation-state
RU
Unknown
Wizard Spider is reportedly associated with Grim Spider and Lunar Spider.
The WIZARD SPIDER threat group is the Russia-based operator of the TrickBot banking malware. This group represents a growing criminal enterprise of which GRIM SPIDER appears to be a subset. The LUNAR SPIDER threat group is the Eastern European-based operator and developer of the commodity banking malware called BokBot (aka IcedID), which was first observed in April 2017. The BokBot malware provides LUNAR SPIDER affiliates with a variety of capabilities to enable credential theft and wire fraud, through the use of webinjects and a malware distribution function.
GRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER, a criminal enterprise of which GRIM SPIDER appears to be a cell. The WIZARD SPIDER threat group, known as the Russia-based operator of the TrickBot banking malware, had focused primarily on wire fraud in the past.
Tecniche Utilizzate (64)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1003.001 | LSASS Memory | - |
| T1003.002 | Security Account Manager | - |
| T1003.003 | NTDS | - |
| T1005 | Data from Local System | - |
| T1016 | System Network Configuration Discovery | - |
| T1018 | Remote System Discovery | - |
| T1021 | Remote Services | - |
| T1021.001 | Remote Desktop Protocol | - |
| T1021.002 | SMB/Windows Admin Shares | - |
| T1021.006 | Windows Remote Management | - |
| T1027.010 | Command Obfuscation | - |
| T1033 | System Owner/User Discovery | - |
| T1036.004 | Masquerade Task or Service | - |
| T1041 | Exfiltration Over C2 Channel | - |
| T1047 | Windows Management Instrumentation | - |
Riferimenti (10)
- labs.sentinelone.com - Top Tier Russian Organized Cybercrime Group Unveils Fileless Stealthy Powertrick Backdoor For High Value Targets
- crowdstrike.com - Big Game Hunting With Ryuk Another Lucrative Targeted Ransomware
- crowdstrike.com - Sin Ful Spiders Wizard Spider And Lunar Spider Sharing The Same Web
- crowdstrike.com - Wizard Spider Lunar Spider Shared Proxy Module
- crowdstrike.com - Wizard Spider Adds New Feature To Ryuk Ransomware
- cybereason.com - Dropping Anchor From A Trickbot Infection To The Discovery Of The Anchor Malware
- fireeye.com - A Nasty Trick From Credential Theft Malware To Business Disruption
- secureworks.com - Gold Ulrick
- secureworks.com - Dyre Banking Trojan
- secureworks.com - How Cyber Adversaries Are Adapting To Exploit The Global Pandemic
Alias (1995)
Malware Utilizzato (21)
Metadata
| ID: | 201 |
| Created: | 13/01/2026 17:48 |
| Updated: | 07/03/2026 04:00 |