G0102: Wizard Spider
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]
Security context for executives and security teams
G0102: Wizard Spider describes [Wizard Spider](https://attack.mitre.org/groups/G0102) is a Russia-based financially motivated threat group originally known for the creation and deployment of [TrickBot](https://attack.mitre.org/software/S0266) since at least 2016. [Wizard Spider](https://attack.mitre.org/groups/G0102) possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.(Citation: CrowdStrike Ryuk January 2019)(Citation: DHS/CISA Ransomware Tar...
Executive priority
G0102: Wizard Spider is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0102: Wizard Spider by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0102: Wizard Spider appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Wizard Spider
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1136.001 | Local AccountSub-technique | Wizard Spider has created local administrator accounts to maintain persistence in compromised networks.[4] |
| Enterprise | T1588.003 | Code Signing CertificatesSub-technique | Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads.CitationDFIR Ryuk 2 Hour Speed Run November 2020[4] |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | Wizard Spider has archived data into ZIP files on compromised machines.[4] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Wizard Spider has used `cmd.exe` to execute commands on a victim's machine.CitationDFIR Ryuk's Return October 2020[4] |
| Enterprise | T1047 | Windows Management Instrumentation | Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.[5][2][7]CitationRed Canary Hospital Thwarted Ryuk October 2020[4] |
| Enterprise | T1588.002 | ToolSub-technique | Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.[7][4] |
| Enterprise | T1543.003 | Windows ServiceSub-technique | Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence.[5][4] |
| Enterprise | T1021.002 | SMB/Windows Admin SharesSub-technique | Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement.CitationDFIR Ryuk 2 Hour Speed Run November 2020CitationDFIR Ryuk's Return October 2020 |
| Enterprise | T1074 | Data Staged | Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules.[5] |
| Enterprise | T1078.002 | Domain AccountsSub-technique | Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network.[7] |
| Enterprise | T1055 | Process Injection | Wizard Spider has used process injection to execute payloads to escalate privileges.[4] |
| Enterprise | T1021 | Remote Services | Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares.[4] |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively.[5][2]CitationDFIR Ryuk 2 Hour Speed Run November 2020[4] |
| Enterprise | T1550.002 | Pass the HashSub-technique | Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally.[4] |
| Enterprise | T1222.001 | Windows PermissionsSub-technique | Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders.CitationSophos New Ryuk Attack October 2020 |
| Enterprise | T1570 | Lateral Tool Transfer | Wizard Spider has used stolen credentials to copy tools into the |
| Enterprise | T1204.002 | Malicious FileSub-technique | |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | |
| Enterprise | T1027.010 | Command ObfuscationSub-technique | Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.[6]CitationDFIR Ryuk's Return October 2020 |
| Enterprise | T1070.004 | File DeletionSub-technique | Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use.[5] |
| Enterprise | T1552.006 | Group Policy PreferencesSub-technique | Wizard Spider has used PowerShell cmdlets `Get-GPPPassword` and `Find-GPOPassword` to find unsecured credentials in a compromised network group policy.[4] |
| Enterprise | T1048.003 | Exfiltration Over Unencrypted Non-C2 ProtocolSub-technique | Wizard Spider has exfiltrated victim information using FTP.CitationDFIR Ryuk's Return October 2020CitationDFIR Ryuk 2 Hour Speed Run November 2020 |
| Enterprise | T1685 | Disable or Modify Tools | Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.[2][7]CitationDFIR Ryuk's Return October 2020[4] |
| Enterprise | T1518.001 | Security Software DiscoverySub-technique | Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine.CitationDFIR Ryuk's Return October 2020 |
| Enterprise | T1218.011 | Rundll32Sub-technique | Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV.[4] |
| Enterprise | T1558.003 | KerberoastingSub-technique | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.CitationDFIR Ryuk's Return October 2020[7][2]CitationDFIR Ryuk 2 Hour Speed Run November 2020[4] |
| Enterprise | T1059.001 | PowerShellSub-technique | Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines.[5] It has also used PowerShell to execute commands and move laterally through a victim network.[2][7]CitationRed Canary Hospital Thwarted Ryuk October 2020[4] |
| Enterprise | T1567.002 | Exfiltration to Cloud StorageSub-technique | Wizard Spider has exfiltrated stolen victim data to various cloud storage providers.[4] |
| Enterprise | T1112 | Modify Registry | Wizard Spider has modified the Registry key |
| Enterprise | T1490 | Inhibit System Recovery | Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin.[4] |
| Enterprise | T1133 | External Remote Services | Wizard Spider has accessed victim networks by using stolen credentials to access the corporate VPN infrastructure.[7] |
| Enterprise | T1547.004 | Winlogon Helper DLLSub-technique | Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.[7] |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf.[5] It has also used common document file names for other malware binaries.[7] |
| Enterprise | T1087.002 | Domain AccountSub-technique | Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data.CitationDFIR Ryuk's Return October 2020[4] |
| Enterprise | T1518.002 | Backup Software DiscoverySub-technique | Wizard Spider has utilized the PowerShell script `Get-DataInfo.ps1` to collect installed backup software information from a compromised machine.[4] |
| Enterprise | T1071.001 | Web ProtocolsSub-technique | Wizard Spider has used HTTP for network communications.[5] |
| Enterprise | T1553.002 | Code SigningSub-technique | Wizard Spider has used Digicert code-signing certificates for some of its malware.CitationDFIR Ryuk 2 Hour Speed Run November 2020 |
| Enterprise | T1136.002 | Domain AccountSub-technique | Wizard Spider has created and used new accounts within a victim's Active Directory environment to maintain persistence.[4] |
| Enterprise | T1074.001 | Local Data StagingSub-technique | Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration.[4] |
| Enterprise | T1557.001 | Name Resolution Poisoning and SMB RelaySub-technique | Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning.[7] |
| Enterprise | T1105 | Ingress Tool Transfer | Wizard Spider can transfer malicious payloads such as ransomware to compromised machines.[4] |
| Enterprise | T1003.003 | NTDSSub-technique | Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.[7][4] |
| Enterprise | T1016 | System Network Configuration Discovery | Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory.CitationSophos New Ryuk Attack October 2020[4] |
| Enterprise | T1585.002 | Email AccountsSub-technique | Wizard Spider has leveraged ProtonMail email addresses in ransom notes when delivering Ryuk ransomware.[4] |
| Enterprise | T1033 | System Owner/User Discovery | Wizard Spider has used "whoami" to identify the local user and their privileges.CitationSophos New Ryuk Attack October 2020 |
| Enterprise | T1078 | Valid Accounts | Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers.[5][4] |
| Enterprise | T1204.001 | Malicious LinkSub-technique | Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing.[2] |
| Enterprise | T1003.001 | LSASS MemorySub-technique | Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne.[4] |
| Enterprise | T1041 | Exfiltration Over C2 Channel | Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.[5][4] |
| Enterprise | T1566.001 | Spearphishing AttachmentSub-technique | |
| Enterprise | T1003.002 | Security Account ManagerSub-technique | Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.[7] |
| Enterprise | T1489 | Service Stop | Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption.CitationDFIR Ryuk's Return October 2020 |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services.[2]CitationDFIR Ryuk 2 Hour Speed Run November 2020 |
| Enterprise | T1018 | Remote System Discovery | Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
| Enterprise | T1005 | Data from Local System | Wizard Spider has collected data from a compromised host prior to exfiltration.[4] |
| Enterprise | T1082 | System Information Discovery | Wizard Spider has used Systeminfo and similar commands to acquire detailed configuration information of a victim's machine. Wizard Spider has also utilized the PowerShell cmdlet `Get-ADComputer` to collect DNS hostnames, last logon dates, and operating system information from Active Directory.CitationDFIR Ryuk's Return October 2020[4] |
| Enterprise | T1555.004 | Windows Credential ManagerSub-technique | Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network.[4] |
| Enterprise | T1135 | Network Share Discovery | Wizard Spider has used the “net view” command to locate mapped network shares.[2] |
| Enterprise | T1569.002 | Service ExecutionSub-technique | Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.CitationDFIR Ryuk's Return October 2020CitationDFIR Ryuk in 5 Hours October 2020[4] |
| Enterprise | T1547.001 | Registry Run Keys / Startup FolderSub-technique | Wizard Spider has established persistence via the Registry key |
Groups, software, and campaigns
S0266: TrickBot
TrickBot is a Trojan spyware program written in C++ that first emerged in September 2016 as a possible successor to Dyre. TrickBot was developed and initially used by Wizard Spider for targeting banking sites in North America, Australia, and throughout Europe; it has since been used against all sectors worldwide as part of "big game hunting" ransomware campaigns.[1][2][3][4]
S0552: AdFind
S0190: BITSAdmin
S9001: SystemBC
SystemBC is a malware family offered as a malware-as-a-service (MaaS) that is used to establish command and control and facilitate follow-on activity, including ransomware deployment.SystemBC executes a variety of tasks including setting up SOCKS5 proxies, maintaining persistence, ingesting malicious files, and handing C2 communication. SystemBC was first detected in 2018, and has been used by Wizard Spider since at least 2020, and by FIN7 since at least 2022.[1][2][3][4][5]
S0521: BloodHound
BloodHound is an Active Directory (AD) reconnaissance tool that can reveal hidden relationships and identify attack paths within an AD environment.[1][2][3]
S0097: Ping
S0534: Bazar
Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.[1]
S0349: LaZagne
S0359: Nltest
S0632: GrimAgent
GrimAgent is a backdoor that has been used before the deployment of Ryuk ransomware since at least 2020; it is likely used by FIN6 and Wizard Spider.[1]
S0024: Dyre
S0446: Ryuk
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 4.1 | Current bundle | 11a9ad6b58d2… | ||
| 19.1 | 4.1 | Older bundle | b5b0e2978bc0… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]CrowdStrike Ryuk January 2019
Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.
Open source URL - [2]DHS/CISA Ransomware Targeting Healthcare October 2020
DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.
Open source URL - [3]CrowdStrike Wizard Spider October 2020
Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021.
Open source URL - [4]Mandiant FIN12 Oct 2021
Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.
Open source URL - [5]CrowdStrike Grim Spider May 2019
John, E. and Carvey, H. (2019, May 30). Unraveling the Spiderweb: Timelining ATT&CK Artifacts Used by GRIM SPIDER. Retrieved May 12, 2020.
Open source URL - [6]FireEye Ryuk and Trickbot January 2019
Goody, K., et al (2019, January 11). A Nasty Trick: From Credential Theft Malware to Business Disruption. Retrieved May 12, 2020.
Open source URL - [7]FireEye KEGTAP SINGLEMALT October 2020
Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.
Open source URL - [8]Microsoft_PistachioTempest_Jan2024
Microsoft. (2024, January 25). Financially Motivated Threat Actor Pistachio Tempest. Retrieved December 15, 2025.
Open source URL - [9]DEV-0193
(Citation: Microsoft Threat Actor Naming July 2023)
- [10]DEV-0237
(Citation: Microsoft_PistachioTempest_Jan2024)
- [11]FIN12
(Citation: Mandiant FIN12 Oct 2021)
- [12]GOLD BLACKBURN
(Citation: Secureworks Gold Blackburn Mar 2022)
- [13]Grim Spider
(Citation: CrowdStrike Ryuk January 2019)(Citation: CrowdStrike Grim Spider May 2019)
- [14]IBM X-Force ITG23 Oct 2021
Villadsen, O., et al. (2021, October 13). Trickbot Rising - Gang Doubles Down on Infection Efforts to Amass Network Footholds. Retrieved June 15, 2023.
Open source URL - [15]ITG23
(Citation: IBM X-Force ITG23 Oct 2021)
- [16]Microsoft Threat Actor Naming July 2023
Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Open source URL - [17]Periwinkle Tempest
(Citation: Microsoft Threat Actor Naming July 2023)
- [18]Pistachio Tempest
(Citation: Microsoft_PistachioTempest_Jan2024)
- [19]Secureworks Gold Blackburn Mar 2022
Secureworks Counter Threat Unit. (2022, March 1). Gold Blackburn Threat Profile. Retrieved June 15, 2023.
Open source URL - [20]TEMP.MixMaster
(Citation: FireEye Ryuk and Trickbot January 2019)
- [21]UNC1878
(Citation: FireEye KEGTAP SINGLEMALT October 2020)
- [22]mitre-attackG0102Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
