LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0102: Wizard Spider

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]

EnterpriseG0102GroupObject v4.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0102: Wizard Spider describes [Wizard Spider](https://attack.mitre.org/groups/G0102) is a Russia-based financially motivated threat group originally known for the creation and deployment of [TrickBot](https://attack.mitre.org/software/S0266) since at least 2016. [Wizard Spider](https://attack.mitre.org/groups/G0102) possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.(Citation: CrowdStrike Ryuk January 2019)(Citation: DHS/CISA Ransomware Tar...

Executive priority

G0102: Wizard Spider is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0102: Wizard Spider by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0102: Wizard Spider appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Wizard Spider

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

60 rows
DomainIDNameRelationship / procedure
EnterpriseT1136.001Local AccountSub-technique

Wizard Spider has created local administrator accounts to maintain persistence in compromised networks.[4]

EnterpriseT1588.003Code Signing CertificatesSub-technique

Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads.CitationDFIR Ryuk 2 Hour Speed Run November 2020[4]

EnterpriseT1560.001Archive via UtilitySub-technique

Wizard Spider has archived data into ZIP files on compromised machines.[4]

EnterpriseT1059.003Windows Command ShellSub-technique

Wizard Spider has used `cmd.exe` to execute commands on a victim's machine.CitationDFIR Ryuk's Return October 2020[4]

EnterpriseT1047Windows Management Instrumentation

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.[5][2][7]CitationRed Canary Hospital Thwarted Ryuk October 2020[4]

EnterpriseT1588.002ToolSub-technique

Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.[7][4]

EnterpriseT1543.003Windows ServiceSub-technique

Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence.[5][4]

EnterpriseT1021.002SMB/Windows Admin SharesSub-technique

Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement.CitationDFIR Ryuk 2 Hour Speed Run November 2020CitationDFIR Ryuk's Return October 2020

EnterpriseT1074Data Staged

Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules.[5]

EnterpriseT1078.002Domain AccountsSub-technique

Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network.[7]

EnterpriseT1055Process Injection

Wizard Spider has used process injection to execute payloads to escalate privileges.[4]

EnterpriseT1021Remote Services

Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares.[4]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively.[5][2]CitationDFIR Ryuk 2 Hour Speed Run November 2020[4]

EnterpriseT1550.002Pass the HashSub-technique

Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally.[4]

EnterpriseT1222.001Windows PermissionsSub-technique

Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders.CitationSophos New Ryuk Attack October 2020

EnterpriseT1570Lateral Tool Transfer

Wizard Spider has used stolen credentials to copy tools into the %TEMP% directory of domain controllers.[5]

EnterpriseT1204.002Malicious FileSub-technique

Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar.[5][3][4]

EnterpriseT1053.005Scheduled TaskSub-technique

Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware.[5][2][7]CitationDFIR Ryuk 2 Hour Speed Run November 2020[4]

EnterpriseT1027.010Command ObfuscationSub-technique

Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.[6]CitationDFIR Ryuk's Return October 2020

EnterpriseT1070.004File DeletionSub-technique

Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use.[5]

EnterpriseT1552.006Group Policy PreferencesSub-technique

Wizard Spider has used PowerShell cmdlets `Get-GPPPassword` and `Find-GPOPassword` to find unsecured credentials in a compromised network group policy.[4]

EnterpriseT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolSub-technique

Wizard Spider has exfiltrated victim information using FTP.CitationDFIR Ryuk's Return October 2020CitationDFIR Ryuk 2 Hour Speed Run November 2020

EnterpriseT1685Disable or Modify Tools

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.[2][7]CitationDFIR Ryuk's Return October 2020[4]

EnterpriseT1518.001Security Software DiscoverySub-technique

Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine.CitationDFIR Ryuk's Return October 2020

EnterpriseT1218.011Rundll32Sub-technique

Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV.[4]

EnterpriseT1558.003KerberoastingSub-technique

Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.CitationDFIR Ryuk's Return October 2020[7][2]CitationDFIR Ryuk 2 Hour Speed Run November 2020[4]

EnterpriseT1059.001PowerShellSub-technique

Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines.[5] It has also used PowerShell to execute commands and move laterally through a victim network.[2][7]CitationRed Canary Hospital Thwarted Ryuk October 2020[4]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Wizard Spider has exfiltrated stolen victim data to various cloud storage providers.[4]

EnterpriseT1112Modify Registry

Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest by setting the UseLogonCredential registry value to 1 in order to force credentials to be stored in clear text in memory. Wizard Spider has also modified the WDigest registry key to allow plaintext credentials to be cached in memory.[5][4]

EnterpriseT1490Inhibit System Recovery

Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin.[4]

EnterpriseT1133External Remote Services

Wizard Spider has accessed victim networks by using stolen credentials to access the corporate VPN infrastructure.[7]

EnterpriseT1547.004Winlogon Helper DLLSub-technique

Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.[7]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf.[5] It has also used common document file names for other malware binaries.[7]

EnterpriseT1087.002Domain AccountSub-technique

Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data.CitationDFIR Ryuk's Return October 2020[4]

EnterpriseT1518.002Backup Software DiscoverySub-technique

Wizard Spider has utilized the PowerShell script `Get-DataInfo.ps1` to collect installed backup software information from a compromised machine.[4]

EnterpriseT1071.001Web ProtocolsSub-technique

Wizard Spider has used HTTP for network communications.[5]

EnterpriseT1553.002Code SigningSub-technique

Wizard Spider has used Digicert code-signing certificates for some of its malware.CitationDFIR Ryuk 2 Hour Speed Run November 2020

EnterpriseT1136.002Domain AccountSub-technique

Wizard Spider has created and used new accounts within a victim's Active Directory environment to maintain persistence.[4]

EnterpriseT1074.001Local Data StagingSub-technique

Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration.[4]

EnterpriseT1557.001Name Resolution Poisoning and SMB RelaySub-technique

Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning.[7]

EnterpriseT1105Ingress Tool Transfer

Wizard Spider can transfer malicious payloads such as ransomware to compromised machines.[4]

EnterpriseT1003.003NTDSSub-technique

Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.[7][4]

EnterpriseT1016System Network Configuration Discovery

Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory.CitationSophos New Ryuk Attack October 2020[4]

EnterpriseT1585.002Email AccountsSub-technique

Wizard Spider has leveraged ProtonMail email addresses in ransom notes when delivering Ryuk ransomware.[4]

EnterpriseT1033System Owner/User Discovery

Wizard Spider has used "whoami" to identify the local user and their privileges.CitationSophos New Ryuk Attack October 2020

EnterpriseT1078Valid Accounts

Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers.[5][4]

EnterpriseT1204.001Malicious LinkSub-technique

Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing.[2]

EnterpriseT1003.001LSASS MemorySub-technique

Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne.[4]

EnterpriseT1041Exfiltration Over C2 Channel

Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.[5][4]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar.[5]CitationRed Canary Hospital Thwarted Ryuk October 2020[4]

EnterpriseT1003.002Security Account ManagerSub-technique

Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.[7]

EnterpriseT1489Service Stop

Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption.CitationDFIR Ryuk's Return October 2020

EnterpriseT1566.002Spearphishing LinkSub-technique

Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services.[2]CitationDFIR Ryuk 2 Hour Speed Run November 2020

EnterpriseT1018Remote System Discovery

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.[6][5][7]CitationRed Canary Hospital Thwarted Ryuk October 2020CitationDFIR Ryuk's Return October 2020[4]

EnterpriseT1005Data from Local System

Wizard Spider has collected data from a compromised host prior to exfiltration.[4]

EnterpriseT1082System Information Discovery

Wizard Spider has used Systeminfo and similar commands to acquire detailed configuration information of a victim's machine. Wizard Spider has also utilized the PowerShell cmdlet `Get-ADComputer` to collect DNS hostnames, last logon dates, and operating system information from Active Directory.CitationDFIR Ryuk's Return October 2020[4]

EnterpriseT1555.004Windows Credential ManagerSub-technique

Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network.[4]

EnterpriseT1135Network Share Discovery

Wizard Spider has used the “net view” command to locate mapped network shares.[2]

EnterpriseT1569.002Service ExecutionSub-technique

Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.CitationDFIR Ryuk's Return October 2020CitationDFIR Ryuk in 5 Hours October 2020[4]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Wizard Spider has established persistence via the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and a shortcut within the startup folder.[2][7]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0266: TrickBot

TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.[1][2][3][4]

Windows
MalwareEnterprise

S9001: SystemBC

SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.SystemBC executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. SystemBC was first detected in 2018, and has been used by Wizard Spider since at least 2020, and by FIN7 since at least 2022.[1][2][3][4][5]

LinuxWindows
ToolEnterprise

S0097: Ping

Ping is an operating system utility commonly used to troubleshoot and verify network connections. [1]

MalwareEnterprise

S0534: Bazar

Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.[1]

Windows
ToolEnterprise

S0349: LaZagne

LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.[1]

LinuxmacOSWindows
ToolEnterprise

S0359: Nltest

Nltest is a Windows command-line utility used to list domain controllers and enumerate domain trusts.[1]

Windows
MalwareEnterprise

S0446: Ryuk

Ryuk is a ransomware designed to target enterprise environments that has been used in attacks since at least 2018. Ryuk shares code similarities with Hermes ransomware.[1][2][3]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
4.1
Created
Modified
Raw hash
11a9ad6b58d22e8c...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.24.1Current bundle11a9ad6b58d2…
19.14.1Older bundleb5b0e2978bc0…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CrowdStrike Ryuk January 2019

    Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.

    Open source URL
  2. [2]
    DHS/CISA Ransomware Targeting Healthcare October 2020

    DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

    Open source URL
  3. [3]
    CrowdStrike Wizard Spider October 2020

    Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021.

    Open source URL
  4. [4]
    Mandiant FIN12 Oct 2021

    Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

    Open source URL
  5. [5]
    CrowdStrike Grim Spider May 2019

    John, E. and Carvey, H. (2019, May 30). Unraveling the Spiderweb: Timelining ATT&CK Artifacts Used by GRIM SPIDER. Retrieved May 12, 2020.

    Open source URL
  6. [6]
    FireEye Ryuk and Trickbot January 2019

    Goody, K., et al (2019, January 11). A Nasty Trick: From Credential Theft Malware to Business Disruption. Retrieved May 12, 2020.

    Open source URL
  7. [7]
    FireEye KEGTAP SINGLEMALT October 2020

    Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.

    Open source URL
  8. [8]
    Microsoft_PistachioTempest_Jan2024

    Microsoft. (2024, January 25). Financially Motivated Threat Actor Pistachio Tempest. Retrieved December 15, 2025.

    Open source URL
  9. [9]
    DEV-0193

    (Citation: Microsoft Threat Actor Naming July 2023)

  10. [10]
    DEV-0237

    (Citation: Microsoft_PistachioTempest_Jan2024)

  11. [11]
    FIN12

    (Citation: Mandiant FIN12 Oct 2021)

  12. [12]
    GOLD BLACKBURN

    (Citation: Secureworks Gold Blackburn Mar 2022)

  13. [13]
    Grim Spider

    (Citation: CrowdStrike Ryuk January 2019)(Citation: CrowdStrike Grim Spider May 2019)

  14. [14]
    IBM X-Force ITG23 Oct 2021

    Villadsen, O., et al. (2021, October 13). Trickbot Rising - Gang Doubles Down on Infection Efforts to Amass Network Footholds. Retrieved June 15, 2023.

    Open source URL
  15. [15]
    ITG23

    (Citation: IBM X-Force ITG23 Oct 2021)

  16. [16]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  17. [17]
    Periwinkle Tempest

    (Citation: Microsoft Threat Actor Naming July 2023)

  18. [18]
    Pistachio Tempest

    (Citation: Microsoft_PistachioTempest_Jan2024)

  19. [19]
    Secureworks Gold Blackburn Mar 2022

    Secureworks Counter Threat Unit. (2022, March 1). Gold Blackburn Threat Profile. Retrieved June 15, 2023.

    Open source URL
  20. [20]
    TEMP.MixMaster

    (Citation: FireEye Ryuk and Trickbot January 2019)

  21. [21]
    UNC1878

    (Citation: FireEye KEGTAP SINGLEMALT October 2020)

  22. [22]
    mitre-attackG0102
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.