Hacker groupG0102

Wizard Spider

Also tracked as UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, DEV-0237

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.

Known attack methods
64
Origin
Russia
Motive
Financial gain
First seen
2016
Source
MITRE ATT&CK

How they break in

Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.

Malware

Families MITRE records this group deploying. Detection names for these are a reasonable place to start.

AnchorBazarCobalt StrikeContiDiavolDyreEmotetGrimAgentRyukSystemBCTrickBot

Tools

Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.

AdFindBITSAdminBloodHoundEmpireLaZagneMimikatzNetNltestPingPsExecRubeus