LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0119: Indrik Spider

Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.[1][2][3]

EnterpriseG0119GroupObject v4.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0119: Indrik Spider describes [Indrik Spider](https://attack.mitre.org/groups/G0119) is a Russia-based cybercriminal group that has been active since at least 2014. [Indrik Spider](https://attack.mitre.org/groups/G0119) initially started with the [Dridex](https://attack.mitre.org/software/S0384) banking Trojan, and then by 2017 they began running ransomware operations using [BitPaymer](https://attack.mitre.org/software/S0570), [WastedLocker](https://attack.mitre.org/software/S0612), and Hades ransomware. Following U.S. sanctions and an indictme...

Executive priority

G0119: Indrik Spider is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0119: Indrik Spider by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0119: Indrik Spider appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Indrik Spider

Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

33 rows
DomainIDNameRelationship / procedure
EnterpriseT1003.001LSASS MemorySub-technique

Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump.CitationSymantec WastedLocker June 2020

EnterpriseT1587.001MalwareSub-technique

Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker.[1]

EnterpriseT1136Create Account

Indrik Spider used wmic.exe to add a new user to the system.CitationSymantec WastedLocker June 2020

EnterpriseT1112Modify Registry

Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities.[4]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors.[1]

EnterpriseT1007System Service Discovery

Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.CitationSymantec WastedLocker June 2020

EnterpriseT1583Acquire Infrastructure

Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments.[4]

EnterpriseT1685Disable or Modify Tools

Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring.CitationSymantec WastedLocker June 2020 Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender.[4] Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services.[4]

EnterpriseT1074.001Local Data StagingSub-technique

Indrik Spider has stored collected data in a .tmp file.CitationSymantec WastedLocker June 2020

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Indrik Spider has used RDP for lateral movement.[4]

EnterpriseT1555.005Password ManagersSub-technique

Indrik Spider has accessed and exported passwords from password managers.[4]

EnterpriseT1590Gather Victim Network Information

Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc.[4]

EnterpriseT1059.001PowerShellSub-technique

Indrik Spider has used PowerShell Empire for execution of malware.[1]CitationSymantec WastedLocker June 2020

EnterpriseT1078.002Domain AccountsSub-technique

Indrik Spider has collected credentials from infected systems, including domain accounts.[1]

EnterpriseT1552.001Credentials In FilesSub-technique

Indrik Spider has searched files to obtain and exfiltrate credentials.[4]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware.[4]

EnterpriseT1059.003Windows Command ShellSub-technique

Indrik Spider has used batch scripts on victim's machines.[1][4]

EnterpriseT1484.001Group Policy ModificationSub-technique

Indrik Spider has used Group Policy Objects to deploy batch scripts.[1][4]

EnterpriseT1047Windows Management Instrumentation

Indrik Spider has used WMIC to execute commands on remote computers.CitationSymantec WastedLocker June 2020

EnterpriseT1078Valid Accounts

Indrik Spider has used valid accounts for initial access and lateral movement.[4] Indrik Spider has also maintained access to the victim environment through the VPN infrastructure.[4]

EnterpriseT1486Data Encrypted for Impact

Indrik Spider has encrypted domain-controlled systems using BitPaymer.[1] Additionally, Indrik Spider used PsExec to execute a ransomware script.[4]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Indrik Spider has used Cobalt Strike to empty log files.CitationSymantec WastedLocker June 2020 Additionally, Indrik Spider has cleared all event logs using `wevutil`.[4]

EnterpriseT1136.001Local AccountSub-technique

Indrik Spider has created local system accounts and has added the accounts to privileged groups.[4]

EnterpriseT1018Remote System Discovery

Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database.CitationSymantec WastedLocker June 2020

EnterpriseT1059.007JavaScriptSub-technique

Indrik Spider has used malicious JavaScript files for several components of their attack.CitationSymantec WastedLocker June 2020

EnterpriseT1585.002Email AccountsSub-technique

Indrik Spider has created email accounts to communicate with their ransomware victims, to include providing payment and decryption details.[1]

EnterpriseT1105Ingress Tool Transfer

Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.[1]CitationSymantec WastedLocker June 2020[4]

EnterpriseT1489Service Stop

Indrik Spider has used PsExec to stop services prior to the execution of ransomware.CitationSymantec WastedLocker June 2020

EnterpriseT1012Query Registry

Indrik Spider has used a service account to extract copies of the `Security` Registry hive.[4]

EnterpriseT1558.003KerberoastingSub-technique

Indrik Spider has conducted Kerberoasting attacks using a module from GitHub.[4]

EnterpriseT1204.002Malicious FileSub-technique

Indrik Spider has attempted to get users to click on a malicious zipped file.CitationSymantec WastedLocker June 2020

EnterpriseT1021.004SSHSub-technique

Indrik Spider has used SSH for lateral movement.[4]

EnterpriseT1584.004ServerSub-technique

Indrik Spider has served fake updates via legitimate websites that have been compromised.[1]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0695: Donut

Donut is an open source framework used to generate position-independent shellcode.[1][2] Donut generated code has been used by multiple threat actors to inject and load malicious payloads into memory.[3]

Windows
ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0363: Empire

Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]

LinuxmacOSWindows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
MalwareEnterprise

S0384: Dridex

Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex).[1][2][3]

Windows
MalwareEnterprise

S0570: BitPaymer

BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. BitPaymer uses a unique encryption key, ransom note, and contact information for each operation. BitPaymer has several indicators suggesting overlap with the Dridex malware and is often delivered via Dridex.[1]

Windows
MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
4.1
Created
Modified
Raw hash
11ca60c100c65f65...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.24.1Current bundle11ca60c100c6…
19.14.1Older bundlea678d30f1382…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Crowdstrike Indrik November 2018

    Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

    Open source URL
  2. [2]
    Crowdstrike EvilCorp March 2021

    Podlosky, A., Feeley, B. (2021, March 17). INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions. Retrieved September 15, 2021.

    Open source URL
  3. [3]
    Treasury EvilCorp Dec 2019

    U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.

    Open source URL
  4. [4]
    Mandiant_UNC2165

    Mandiant Intelligence. (2022, June 2). To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions. Retrieved July 29, 2024.

    Open source URL
  5. [5]
    DEV-0243

    (Citation: Microsoft Threat Actor Naming July 2023)

  6. [6]
    Evil Corp

    (Citation: Crowdstrike EvilCorp March 2021)(Citation: Treasury EvilCorp Dec 2019)

  7. [7]
    Manatee Tempest

    (Citation: Microsoft Threat Actor Naming July 2023)

  8. [8]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  9. [9]
    UNC2165

    (Citation: Mandiant_UNC2165)

  10. [10]
    mitre-attackG0119
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.