LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0102: Wizard Spider

MITRE ATT&CK G0102: Wizard Spider Group details, with detection guidance, relationships and mapped CVEs.

EnterpriseG0102GroupObject v4.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Wizard Spider matters because ATT&CK describes it as a financially motivated group associated with TrickBot and ransomware campaigns affecting major corporations and hospitals. For leaders, the practical issue is not a single malware name; it is whether the organization can detect and contain a Windows/Active Directory-centered intrusion path before credential theft, lateral movement tooling, and ransomware deployment create business disruption.

Executive priority

Prioritize this as an operational resilience and incident-readiness concern. The ATT&CK relationships connect Wizard Spider to credential dumping, Active Directory reconnaissance, remote execution/admin utilities, backdoors, downloaders, and ransomware families such as Ryuk, Conti, and Diavol. Executives should ask whether identity controls, endpoint visibility, backup recovery, ransomware playbooks, and healthcare or critical operations continuity evidence are tested together rather than managed as separate control areas.

Technical view

ATT&CK provides no group-level detection text or platforms, so teams should validate coverage through the related software and technique relationships. Emphasis should be on Windows and Active Directory telemetry where supported by related objects: LSASS access, Mimikatz/LaZagne/Rubeus-style credential activity, BloodHound/AdFind/Nltest/Net domain discovery, PsExec-style remote execution, BITSAdmin transfer activity, Cobalt Strike/Empire/SystemBC/Anchor/Bazar/TrickBot/Emotet-related execution or C2 indicators, and ransomware precursors associated with Ryuk, Conti, Diavol, and GrimAgent. Treat legitimate admin tools such as PsExec, Net, Ping, BITSAdmin, Nltest, and AdFind as high-context detections requiring baselines, user/process lineage, and change-window awareness.

Likely telemetry

  • Endpoint process creation and command-line logs on Windows systems
  • LSASS access and credential dumping alerts or EDR events
  • Windows authentication, Kerberos, and privileged logon events
  • Active Directory query and domain trust enumeration evidence
  • Remote service creation, admin share, and PsExec-like execution logs

Detection direction

  • Map detections to the related ATT&CK objects rather than relying on the Wizard Spider group object, because no official detection guidance is supplied.
  • Validate whether credential-access coverage includes LSASS memory access and known credential tools such as Mimikatz, LaZagne, and Rubeus.
  • Tune detections for living-off-the-land and dual-use utilities by correlating command line, parent process, user role, host criticality, and lateral movement context.
  • Baseline legitimate Active Directory administration so BloodHound, AdFind, Nltest, and Net-style enumeration stands out when performed by unusual users or hosts.
  • Correlate downloader/backdoor activity with follow-on lateral movement and ransomware staging instead of treating each alert as isolated.

Mitigation priorities

  • Harden identity first: reduce standing privilege, protect domain controllers, monitor privileged sessions, and restrict credential exposure on Windows endpoints.
  • Limit and monitor administrative remote execution paths, including PsExec-like behavior and administrative shares.
  • Control use of dual-use tools through allowlisting, least privilege, and logging rather than assuming all instances are malicious.
  • Strengthen endpoint prevention and response coverage on systems that can materially affect business continuity.
  • Segment critical services and validate that ransomware cannot easily propagate from user workstations into core operations.
Additional notes and limits

This take is based on the ATT&CK Wizard Spider intrusion-set object and its supplied relationships. The group has many aliases, including UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, and DEV-0237. The relationship set strongly emphasizes Windows, Active Directory, credential access, remote execution, downloaders/backdoors, and ransomware operations. Healthcare relevance is supported by the official description and DHS/CISA ransomware targeting healthcare reference, but local sector exposure must be assessed by the organization.

ATT&CK does not provide official detection text, group-level tactics, or group-level platforms for this object. Related software platforms indicate where defensive validation is likely relevant, but they do not prove activity in any specific environment. This summary does not assert current exploitation, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Wizard Spider

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
4.1
Created
Modified
Raw hash
b5b0e2978bc05f29...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.