FORENSIA

THREAT_ACTOR · G0102

Wizard Spider

Also known as: Wizard Spider, UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, DEV-0237

Profile

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.

MITRE ATT&CK ↗

Techniques

64 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1003.002 Security Account ManagerT1003.003 NTDST1005 Data from Local SystemT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021 Remote ServicesT1021.001 Remote Desktop ProtocolT1021.002 SMB/Windows Admin SharesT1021.006 Windows Remote ManagementT1027.010 Command ObfuscationT1033 System Owner/User DiscoveryT1036.004 Masquerade Task or ServiceT1041 Exfiltration Over C2 ChannelT1047 Windows Management InstrumentationT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1053.005 Scheduled TaskT1055 Process InjectionT1055.001 Dynamic-link Library InjectionT1059.001 PowerShellT1059.003 Windows Command ShellT1070.004 File DeletionT1071.001 Web ProtocolsT1074 Data StagedT1074.001 Local Data StagingT1078 Valid AccountsT1078.002 Domain AccountsT1082 System Information DiscoveryT1087.002 Domain AccountT1105 Ingress Tool TransferT1112 Modify RegistryT1133 External Remote ServicesT1135 Network Share DiscoveryT1136.001 Local AccountT1136.002 Domain AccountT1197 BITS JobsT1204.001 Malicious LinkT1204.002 Malicious FileT1210 Exploitation of Remote ServicesT1218.011 Rundll32T1222.001 Windows PermissionsT1489 Service StopT1490 Inhibit System RecoveryT1518.001 Security Software DiscoveryT1518.002 Backup Software DiscoveryT1543.003 Windows ServiceT1547.001 Registry Run Keys / Startup FolderT1547.004 Winlogon Helper DLLT1550.002 Pass the HashT1552.006 Group Policy PreferencesT1553.002 Code SigningT1555.004 Windows Credential ManagerT1557.001 Name Resolution Poisoning and SMB RelayT1558.003 KerberoastingT1560.001 Archive via UtilityT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1567.002 Exfiltration to Cloud StorageT1569.002 Service ExecutionT1570 Lateral Tool TransferT1585.002 Email AccountsT1588.002 ToolT1588.003 Code Signing CertificatesT1685 Disable or Modify Tools

Software

22 malware/tools attributed to this actor.

MimikatzDyrePsExecNetPingCobalt StrikeBITSAdminTrickBotLaZagneNltestEmpireEmotetRyukAnchorBloodHoundBazarAdFindContiGrimAgentDiavolRubeusSystemBC

Related corpus activity

10,340 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Wizard Spider.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-2492cve852
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2022-47945cve851
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,340.