Threat group.View on attack.mitre.org
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump. |
| T1007 System Service Discovery |
Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system. |
| T1012 Query Registry |
Indrik Spider has used a service account to extract copies of the `Security` Registry hive. |
| T1018 Remote System Discovery |
Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database. |
| T1021.001 Remote Desktop Protocol |
Indrik Spider has used RDP for lateral movement. |
| T1021.004 SSH |
Indrik Spider has used SSH for lateral movement. |
| T1036.005 Match Legitimate Resource Name or Location |
Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors. |
| T1047 Windows Management Instrumentation |
Indrik Spider has used WMIC to execute commands on remote computers. |
| T1059.001 PowerShell |
Indrik Spider has used PowerShell Empire for execution of malware. |
| T1059.003 Windows Command Shell |
Indrik Spider has used batch scripts on victim's machines. |
| T1059.007 JavaScript |
Indrik Spider has used malicious JavaScript files for several components of their attack. |
| T1074.001 Local Data Staging |
Indrik Spider has stored collected data in a .tmp file. |
| T1078 Valid Accounts |
Indrik Spider has used valid accounts for initial access and lateral movement. Indrik Spider has also maintained access to the victim environment through the VPN infrastructure. |
| T1078.002 Domain Accounts |
Indrik Spider has collected credentials from infected systems, including domain accounts. |
| T1105 Ingress Tool Transfer |
Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.