← threatfilter.dev / all groups / Indrik Spider
Indrik Spider
Also known as: Evil Corp · Manatee Tempest · DEV-0243 · UNC2165
Overview
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 33 techniques across 13 tactics
Reconnaissance
Resource Development
-
T1583Acquire Infrastructure -
T1584.004Server -
T1585.002Email Accounts -
T1587.001Malware
Execution
-
T1047Windows Management Instrumentation -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.007JavaScript -
T1204.002Malicious File
Persistence
-
T1136Create Account -
T1136.001Local Account
Stealth
-
T1036.005Match Legitimate Resource Name or Location -
T1078Valid Accounts -
T1078.002Domain Accounts
Defense Impairment
-
T1112Modify Registry -
T1484.001Group Policy Modification -
T1685Disable or Modify Tools -
T1685.005Clear Windows Event Logs
Credential Access
-
T1003.001LSASS Memory -
T1552.001Credentials In Files -
T1555.005Password Managers -
T1558.003Kerberoasting
Discovery
-
T1007System Service Discovery -
T1012Query Registry -
T1018Remote System Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.004SSH
Collection
-
T1074.001Local Data Staging
Command and Control
-
T1105Ingress Tool Transfer
Exfiltration
-
T1567.002Exfiltration to Cloud Storage
Impact
-
T1486Data Encrypted for Impact -
T1489Service Stop
Tools & malware (8)
Donut · Mimikatz · Empire · PsExec · Dridex · WastedLocker · BitPaymer · Cobalt Strike
Reporting (3)
- How Microsoft names threat actors — Microsoft
- To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions — Mandiant Intelligence
- INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions — Podlosky, A., Feeley, B