THREAT_ACTOR · G0119
Indrik Spider
Also known as: Indrik Spider, Evil Corp, Manatee Tempest, DEV-0243, UNC2165
Profile
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.
MITRE ATT&CK ↗Techniques
33 ATT&CK techniques attributed to this actor.
Software
8 malware/tools attributed to this actor.
Related corpus activity
9,875 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Indrik Spider.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2025-12057 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-3844 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2025-34085 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,875.