Wizard Spider

APT / StateG0102 ↗
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)64
SourceMITRE ATT&CK
State sponsor: Russian FederationTarget categories: Defense, Financial, Government, Healthcare, Telecommunications
Targeted regions: Australia · Bahamas · Canada · Costa Rica · France · Germany · India · Ireland · Italy · Japan +8
Also known as:DEV-0193DEV-0237FIN12GOLD BLACKBURNGrim SpiderITG23Periwinkle TempestPistachio TempestStorm-0193Storm-0230TEMP.MixMasterTrickbot LLCUNC1878UNC2053

About the group

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity79
Impact: High
T1566.001T1047T1133T1003.001T1005T1041ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceExternal RemoteServicesCREDCredential accessLSASS MemoryCOLLCollectionData from LocalSystemEXFILExfiltrationExfiltration OverC2 ChannelIMPACTImpactService Stop

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 64

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 4

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 8

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port45.76.165.219:443SystemBCthreatfox
ip:port45.86.230.112:4001SystemBCthreatfox
domainpaladin5.comSystemBCthreatfox
domainanzo11rikasha22b.pwSystemBCthreatfox
domainkall4234ribk3assa.pwSystemBCthreatfox
ip:port94.232.46.202:4321SystemBCthreatfox
sha256_hash1eb027a9844495e9a3c64bc0c7ea645058933a9b18cc98ff3f42a7b1a9142753SystemBCmalwarebazaar
ip:port34.171.171.32:4001SystemBCthreatfox

Wizard Spider uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →