Indrik Spider
Also known as: Evil Corp · Manatee Tempest · DEV-0243 · UNC2165
Overview
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.
Naming & attribution
Indrik Spider is tracked under 5 names across the industry. It uses 33 documented ATT&CK techniques — more than 70% of the 174 groups tracked here. Activity attributed since at least 2014.
| Name | First reported by |
|---|---|
| Evil Corp | Podlosky, A., Feeley, B |
| Manatee Tempest | Microsoft |
| DEV-0243 | Microsoft |
| UNC2165 | Mandiant Intelligence |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1136Create Account — used by 3 of 174 groups -
T1558.003Kerberoasting — used by 3 of 174 groups -
T1590Gather Victim Network Information — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Aquatic Panda China — 13 shared techniques (24% overlap)
- Wizard Spider Russia — 18 shared techniques (23% overlap)
- Silence — 11 shared techniques (22% overlap)
- Fox Kitten Iran — 13 shared techniques (21% overlap)
- FIN8 — 12 shared techniques (21% overlap)
- Play — 10 shared techniques (20% overlap)
Malware families with current indicators
2 families attributed to Indrik Spider, carrying 1,009 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Dridex 987 indicators
- WastedLocker 22 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Custom malware/implant development — ATT&CK: 4 attributed custom malware families
TTPs — 33 techniques across 13 tactics
Reconnaissance
Resource Development
-
T1583Acquire Infrastructure -
T1584.004Server -
T1585.002Email Accounts -
T1587.001Malware
Execution
-
T1047Windows Management Instrumentation -
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.007JavaScript -
T1204.002Malicious File
Persistence
-
T1136Create Account -
T1136.001Local Account
Stealth
-
T1036.005Match Legitimate Resource Name or Location -
T1078Valid Accounts -
T1078.002Domain Accounts
Defense Impairment
-
T1112Modify Registry -
T1484.001Group Policy Modification -
T1685Disable or Modify Tools -
T1685.005Clear Windows Event Logs
Credential Access
-
T1003.001LSASS Memory -
T1552.001Credentials In Files -
T1555.005Password Managers -
T1558.003Kerberoasting
Discovery
-
T1007System Service Discovery -
T1012Query Registry -
T1018Remote System Discovery
Lateral Movement
-
T1021.001Remote Desktop Protocol -
T1021.004SSH
Collection
-
T1074.001Local Data Staging
Command and Control
-
T1105Ingress Tool Transfer
Exfiltration
-
T1567.002Exfiltration to Cloud Storage
Impact
-
T1486Data Encrypted for Impact -
T1489Service Stop
Tools & malware (8)
Donut · Mimikatz · Empire · PsExec · Dridex · WastedLocker · BitPaymer · Cobalt Strike
Reporting (3)
- How Microsoft names threat actors — Microsoft
- To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions — Mandiant Intelligence
- INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions — Podlosky, A., Feeley, B