G0119: Indrik Spider
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.[1][2][3]
Security context for executives and security teams
G0119: Indrik Spider describes [Indrik Spider](https://attack.mitre.org/groups/G0119) is a Russia-based cybercriminal group that has been active since at least 2014. [Indrik Spider](https://attack.mitre.org/groups/G0119) initially started with the [Dridex](https://attack.mitre.org/software/S0384) banking Trojan, and then by 2017 they began running ransomware operations using [BitPaymer](https://attack.mitre.org/software/S0570), [WastedLocker](https://attack.mitre.org/software/S0612), and Hades ransomware. Following U.S. sanctions and an indictme...
Executive priority
G0119: Indrik Spider is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G0119: Indrik Spider by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G0119: Indrik Spider appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Indrik Spider
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.[1][2][3]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1003.001 | LSASS MemorySub-technique | Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump.CitationSymantec WastedLocker June 2020 |
| Enterprise | T1587.001 | MalwareSub-technique | Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker.[1] |
| Enterprise | T1136 | Create Account | Indrik Spider used |
| Enterprise | T1112 | Modify Registry | Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities.[4] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors.[1] |
| Enterprise | T1007 | System Service Discovery | Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.CitationSymantec WastedLocker June 2020 |
| Enterprise | T1583 | Acquire Infrastructure | Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments.[4] |
| Enterprise | T1685 | Disable or Modify Tools | Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring.CitationSymantec WastedLocker June 2020 Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender.[4] Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services.[4] |
| Enterprise | T1074.001 | Local Data StagingSub-technique | Indrik Spider has stored collected data in a .tmp file.CitationSymantec WastedLocker June 2020 |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | Indrik Spider has used RDP for lateral movement.[4] |
| Enterprise | T1555.005 | Password ManagersSub-technique | Indrik Spider has accessed and exported passwords from password managers.[4] |
| Enterprise | T1590 | Gather Victim Network Information | Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc.[4] |
| Enterprise | T1059.001 | PowerShellSub-technique | Indrik Spider has used PowerShell Empire for execution of malware.[1]CitationSymantec WastedLocker June 2020 |
| Enterprise | T1078.002 | Domain AccountsSub-technique | Indrik Spider has collected credentials from infected systems, including domain accounts.[1] |
| Enterprise | T1552.001 | Credentials In FilesSub-technique | Indrik Spider has searched files to obtain and exfiltrate credentials.[4] |
| Enterprise | T1567.002 | Exfiltration to Cloud StorageSub-technique | Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware.[4] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Indrik Spider has used batch scripts on victim's machines.[1][4] |
| Enterprise | T1484.001 | Group Policy ModificationSub-technique | Indrik Spider has used Group Policy Objects to deploy batch scripts.[1][4] |
| Enterprise | T1047 | Windows Management Instrumentation | Indrik Spider has used WMIC to execute commands on remote computers.CitationSymantec WastedLocker June 2020 |
| Enterprise | T1078 | Valid Accounts | Indrik Spider has used valid accounts for initial access and lateral movement.[4] Indrik Spider has also maintained access to the victim environment through the VPN infrastructure.[4] |
| Enterprise | T1486 | Data Encrypted for Impact | Indrik Spider has encrypted domain-controlled systems using BitPaymer.[1] Additionally, Indrik Spider used PsExec to execute a ransomware script.[4] |
| Enterprise | T1685.005 | Clear Windows Event LogsSub-technique | Indrik Spider has used Cobalt Strike to empty log files.CitationSymantec WastedLocker June 2020 Additionally, Indrik Spider has cleared all event logs using `wevutil`.[4] |
| Enterprise | T1136.001 | Local AccountSub-technique | Indrik Spider has created local system accounts and has added the accounts to privileged groups.[4] |
| Enterprise | T1018 | Remote System Discovery | Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database.CitationSymantec WastedLocker June 2020 |
| Enterprise | T1059.007 | JavaScriptSub-technique | Indrik Spider has used malicious JavaScript files for several components of their attack.CitationSymantec WastedLocker June 2020 |
| Enterprise | T1585.002 | Email AccountsSub-technique | Indrik Spider has created email accounts to communicate with their ransomware victims, to include providing payment and decryption details.[1] |
| Enterprise | T1105 | Ingress Tool Transfer | Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.[1]CitationSymantec WastedLocker June 2020[4] |
| Enterprise | T1489 | Service Stop | Indrik Spider has used PsExec to stop services prior to the execution of ransomware.CitationSymantec WastedLocker June 2020 |
| Enterprise | T1012 | Query Registry | Indrik Spider has used a service account to extract copies of the `Security` Registry hive.[4] |
| Enterprise | T1558.003 | KerberoastingSub-technique | Indrik Spider has conducted Kerberoasting attacks using a module from GitHub.[4] |
| Enterprise | T1204.002 | Malicious FileSub-technique | Indrik Spider has attempted to get users to click on a malicious zipped file.CitationSymantec WastedLocker June 2020 |
| Enterprise | T1021.004 | SSHSub-technique | Indrik Spider has used SSH for lateral movement.[4] |
| Enterprise | T1584.004 | ServerSub-technique | Indrik Spider has served fake updates via legitimate websites that have been compromised.[1] |
Groups, software, and campaigns
S0695: Donut
S0002: Mimikatz
S0363: Empire
Empire is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents are written in pure PowerShell for Windows and Python for Linux/macOS. Empire was one of five tools singled out by a joint report on public hacking tools being widely used by adversaries.[1][2][3]
S0029: PsExec
S0384: Dridex
Dridex is a prolific banking Trojan that first appeared in 2014. By December 2019, the US Treasury estimated Dridex had infected computers in hundreds of banks and financial institutions in over 40 countries, leading to more than $100 million in theft. Dridex was created from the source code of the Bugat banking Trojan (also known as Cridex).[1][2][3]
S0612: WastedLocker
WastedLocker is a ransomware family attributed to Indrik Spider that has been used since at least May 2020. WastedLocker has been used against a broad variety of sectors, including manufacturing, information technology, and media.[1][2][3]
S0570: BitPaymer
BitPaymer is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. BitPaymer uses a unique encryption key, ransom note, and contact information for each operation. BitPaymer has several indicators suggesting overlap with the Dridex malware and is often delivered via Dridex.[1]
S0154: Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 4.1 | Current bundle | 11ca60c100c6… | ||
| 19.1 | 4.1 | Older bundle | a678d30f1382… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Crowdstrike Indrik November 2018
Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.
Open source URL - [2]Crowdstrike EvilCorp March 2021
Podlosky, A., Feeley, B. (2021, March 17). INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions. Retrieved September 15, 2021.
Open source URL - [3]Treasury EvilCorp Dec 2019
U.S. Department of Treasury. (2019, December 5). Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware. Retrieved September 15, 2021.
Open source URL - [4]Mandiant_UNC2165
Mandiant Intelligence. (2022, June 2). To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions. Retrieved July 29, 2024.
Open source URL - [5]DEV-0243
(Citation: Microsoft Threat Actor Naming July 2023)
- [6]Evil Corp
(Citation: Crowdstrike EvilCorp March 2021)(Citation: Treasury EvilCorp Dec 2019)
- [7]Manatee Tempest
(Citation: Microsoft Threat Actor Naming July 2023)
- [8]Microsoft Threat Actor Naming July 2023
Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Open source URL - [9]UNC2165
(Citation: Mandiant_UNC2165)
- [10]mitre-attackG0119Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
