ATT&CKGroupsIndrik Spider

Indrik Spider

G0119

Threat group.View on attack.mitre.org

About this group

Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.

Techniques used33

Procedure examples33

TechniqueProcedure example
T1003.001
LSASS Memory

Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump.

T1007
System Service Discovery

Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.

T1012
Query Registry

Indrik Spider has used a service account to extract copies of the `Security` Registry hive.

T1018
Remote System Discovery

Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database.

T1021.001
Remote Desktop Protocol

Indrik Spider has used RDP for lateral movement.

T1021.004
SSH

Indrik Spider has used SSH for lateral movement.

T1036.005
Match Legitimate Resource Name or Location

Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors.

T1047
Windows Management Instrumentation

Indrik Spider has used WMIC to execute commands on remote computers.

T1059.001
PowerShell

Indrik Spider has used PowerShell Empire for execution of malware.

T1059.003
Windows Command Shell

Indrik Spider has used batch scripts on victim's machines.

T1059.007
JavaScript

Indrik Spider has used malicious JavaScript files for several components of their attack.

T1074.001
Local Data Staging

Indrik Spider has stored collected data in a .tmp file.

T1078
Valid Accounts

Indrik Spider has used valid accounts for initial access and lateral movement. Indrik Spider has also maintained access to the victim environment through the VPN infrastructure.

T1078.002
Domain Accounts

Indrik Spider has collected credentials from infected systems, including domain accounts.

T1105
Ingress Tool Transfer

Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.

View all 33 procedure examples

Software8

Campaigns0

None recorded.

References3

  1. Crowdstrike EvilCorp March 2021 Open source
    Podlosky, A., Feeley, B. (2021, March 17). INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions. Retrieved September 15, 2021.
  2. Crowdstrike Indrik November 2018 Open source
    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.
  3. Treasury EvilCorp Dec 2019 Open source
    U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.