← Back to Actors
Wizard Spider
Wizard SpiderUNC1878TEMP.MixMasterGrim SpiderFIN12GOLD BLACKBURNITG23Periwinkle TempestDEV-0193Pistachio TempestDEV-0237
[Wizard Spider](https://attack.mitre.org/groups/G0102) is a Russia-based financially motivated threat group originally known for the creation and deployment of [TrickBot](https://attack.mitre.org/software/S0266) since at least 2016. [Wizard Spider](https://attack.mitre.org/groups/G0102) possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.(Citation: CrowdStrike Ryuk January 2019)(Citation: DHS/CISA Ransomware Targeting Healthcare October 2020)(Citation: CrowdStrike Wizard Spider October 2020...
65
Techniques
62
Covered
3
Gaps
95%
Coverage
Coverage62/65
COVERED (62)
T1003.001LSASS Memory111 det.T1003.002Security Account Manager49 det.T1003.003NTDS36 det.T1005Data from Local System51 det.T1016System Network Configuration Discovery41 det.T1018Remote System Discovery51 det.T1021Remote Services105 det.T1021.001Remote Desktop Protocol54 det.T1021.002SMB/Windows Admin Shares74 det.T1021.006Windows Remote Management22 det.T1027.010Command Obfuscation38 det.T1033System Owner/User Discovery62 det.T1036.004Masquerade Task or Service7 det.T1041Exfiltration Over C2 Channel32 det.T1047Windows Management Instrumentation88 det.T1048.003Exfiltration Over Unencrypted Non-C2 Protocol23 det.T1053.005Scheduled Task100 det.T1055Process Injection82 det.T1055.001Dynamic-link Library Injection13 det.T1059.001PowerShell376 det.T1059.003Windows Command Shell87 det.T1070.004File Deletion45 det.T1071.001Web Protocols81 det.T1074Data Staged12 det.T1074.001Local Data Staging10 det.T1078Valid Accounts306 det.T1078.002Domain Accounts28 det.T1082System Information Discovery88 det.T1087.002Domain Account58 det.T1105Ingress Tool Transfer191 det.T1112Modify Registry205 det.T1133External Remote Services77 det.T1135Network Share Discovery20 det.T1136.001Local Account45 det.T1136.002Domain Account13 det.T1197BITS Jobs25 det.T1204.001Malicious Link11 det.T1204.002Malicious File461 det.T1210Exploitation of Remote Services37 det.T1218.011Rundll3276 det.T1222.001Windows Permissions23 det.T1489Service Stop58 det.T1490Inhibit System Recovery63 det.T1518.001Security Software Discovery11 det.T1543.003Windows Service80 det.T1547.001Registry Run Keys / Startup Folder53 det.T1547.004Winlogon Helper DLL4 det.T1550.002Pass the Hash10 det.T1552.006Group Policy Preferences9 det.T1553.002Code Signing4 det.T1555.004Windows Credential Manager9 det.T1557.001Name Resolution Poisoning and SMB Relay23 det.T1558.003Kerberoasting35 det.T1560.001Archive via Utility27 det.T1562.001Disable or Modify Tools325 det.T1566.001Spearphishing Attachment1055 det.T1566.002Spearphishing Link1086 det.T1567.002Exfiltration to Cloud Storage31 det.T1569.002Service Execution65 det.T1570Lateral Tool Transfer23 det.T1588.002Tool13 det.T1685Disable or Modify Tools281 det.