NEW: Group Profiler — instant APT intel lookup. Try it →

Indrik Spider

G0119 Russia MITRE ATT&CK →

Also known as: Evil Corp · Manatee Tempest · DEV-0243 · UNC2165

Overview

Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.

Naming & attribution

Indrik Spider is tracked under 5 names across the industry. It uses 33 documented ATT&CK techniques — more than 70% of the 174 groups tracked here. Activity attributed since at least 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Evil CorpPodlosky, A., Feeley, B
Manatee TempestMicrosoft
DEV-0243Microsoft
UNC2165Mandiant Intelligence

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1136 Create Account — used by 3 of 174 groups
  • T1558.003 Kerberoasting — used by 3 of 174 groups
  • T1590 Gather Victim Network Information — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Aquatic Panda China — 13 shared techniques (24% overlap)
  • Wizard Spider Russia — 18 shared techniques (23% overlap)
  • Silence — 11 shared techniques (22% overlap)
  • Fox Kitten Iran — 13 shared techniques (21% overlap)
  • FIN8 — 12 shared techniques (21% overlap)
  • Play — 10 shared techniques (20% overlap)

Malware families with current indicators

2 families attributed to Indrik Spider, carrying 1,009 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Dridex 987 indicators
  • WastedLocker 22 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Custom malware/implant development — ATT&CK: 4 attributed custom malware families

TTPs — 33 techniques across 13 tactics

Reconnaissance

Resource Development

Execution

Persistence

Credential Access

Lateral Movement

Collection

Command and Control

Exfiltration

Tools & malware (8)

Donut · Mimikatz · Empire · PsExec · Dridex · WastedLocker · BitPaymer · Cobalt Strike

Reporting (3)