Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Evil Corp, Manatee Tempest, DEV-0243, UNC2165
33
techniques
8
software
11,201
corpus matches
profile
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.
techniques
33 attributed · most-instrumented first
software
8 malware & tools attributed
Mimikatz
S0002
PsExec
S0029
Cobalt Strike
S0154
Empire
S0363
Dridex
S0384
BitPaymer
S0570
WastedLocker
S0612
Donut
S0695
read this carefully
11,201 corpus matches is not attribution
That count is indicators which exhibit techniques Indrik Spider is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+21 more techniques
showing 30 of 11,201
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.