G0102: Wizard Spider
MITRE ATT&CK G0102: Wizard Spider Group details, with detection guidance, relationships and mapped CVEs.
Security context for executives and security teams
Wizard Spider matters because ATT&CK describes it as a financially motivated group associated with TrickBot and ransomware campaigns affecting major corporations and hospitals. For leaders, the practical issue is not a single malware name; it is whether the organization can detect and contain a Windows/Active Directory-centered intrusion path before credential theft, lateral movement tooling, and ransomware deployment create business disruption.
Executive priority
Prioritize this as an operational resilience and incident-readiness concern. The ATT&CK relationships connect Wizard Spider to credential dumping, Active Directory reconnaissance, remote execution/admin utilities, backdoors, downloaders, and ransomware families such as Ryuk, Conti, and Diavol. Executives should ask whether identity controls, endpoint visibility, backup recovery, ransomware playbooks, and healthcare or critical operations continuity evidence are tested together rather than managed as separate control areas.
Technical view
ATT&CK provides no group-level detection text or platforms, so teams should validate coverage through the related software and technique relationships. Emphasis should be on Windows and Active Directory telemetry where supported by related objects: LSASS access, Mimikatz/LaZagne/Rubeus-style credential activity, BloodHound/AdFind/Nltest/Net domain discovery, PsExec-style remote execution, BITSAdmin transfer activity, Cobalt Strike/Empire/SystemBC/Anchor/Bazar/TrickBot/Emotet-related execution or C2 indicators, and ransomware precursors associated with Ryuk, Conti, Diavol, and GrimAgent. Treat legitimate admin tools such as PsExec, Net, Ping, BITSAdmin, Nltest, and AdFind as high-context detections requiring baselines, user/process lineage, and change-window awareness.
Likely telemetry
- Endpoint process creation and command-line logs on Windows systems
- LSASS access and credential dumping alerts or EDR events
- Windows authentication, Kerberos, and privileged logon events
- Active Directory query and domain trust enumeration evidence
- Remote service creation, admin share, and PsExec-like execution logs
Detection direction
- Map detections to the related ATT&CK objects rather than relying on the Wizard Spider group object, because no official detection guidance is supplied.
- Validate whether credential-access coverage includes LSASS memory access and known credential tools such as Mimikatz, LaZagne, and Rubeus.
- Tune detections for living-off-the-land and dual-use utilities by correlating command line, parent process, user role, host criticality, and lateral movement context.
- Baseline legitimate Active Directory administration so BloodHound, AdFind, Nltest, and Net-style enumeration stands out when performed by unusual users or hosts.
- Correlate downloader/backdoor activity with follow-on lateral movement and ransomware staging instead of treating each alert as isolated.
Mitigation priorities
- Harden identity first: reduce standing privilege, protect domain controllers, monitor privileged sessions, and restrict credential exposure on Windows endpoints.
- Limit and monitor administrative remote execution paths, including PsExec-like behavior and administrative shares.
- Control use of dual-use tools through allowlisting, least privilege, and logging rather than assuming all instances are malicious.
- Strengthen endpoint prevention and response coverage on systems that can materially affect business continuity.
- Segment critical services and validate that ransomware cannot easily propagate from user workstations into core operations.
Additional notes and limits
This take is based on the ATT&CK Wizard Spider intrusion-set object and its supplied relationships. The group has many aliases, including UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, and DEV-0237. The relationship set strongly emphasizes Windows, Active Directory, credential access, remote execution, downloaders/backdoors, and ransomware operations. Healthcare relevance is supported by the official description and DHS/CISA ransomware targeting healthcare reference, but local sector exposure must be assessed by the organization.
ATT&CK does not provide official detection text, group-level tactics, or group-level platforms for this object. Related software platforms indicate where defensive validation is likely relevant, but they do not prove activity in any specific environment. This summary does not assert current exploitation, customer exposure, or guaranteed detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Wizard Spider
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
