Adversary

Wizard Spider

ORIGIN

Eastern Europe, Russian Federation

Community Identifiers

TrickBot, TrickLoader, TheTrick, TotBrick, Ryuk, UNC1878, Anchor, DNS, Conti, BazarLoader, Kegtap

Wizard Spider is a criminal group behind the core development and distribution of a sophisticated arsenal of criminal tools, that allow them to run multiple different types of operations.

The group surfaced in September 2016 with their commodity banking malware most commonly known as TrickBot. Their operations changed significantly in August 2018 when they began running targeted ransomware operations using Ryuk, followed by Conti ransomware since May 2020.

Wizard Spider’s corpus of malware is not openly advertised on criminal forums indicating that Wizard Spider likely only sells access to, or works alongside, trusted criminal groups. Origins of Wizard Spider’s operations are very similar to those of the actor that operated the Dyre malware, which ceased activity in November 2015. CrowdStrike Intelligence assesses with high confidence that some members of the former Dyre group play a key role in Wizard Spider.

Other tools operated by Wizard Spider, not already mentioned above, include:

  • Anchor
  • Sidoh
  • Gophe
  • RelayMTA
  • MagneticScraper
  • BazarLoader

Technical Tradecraft

  • TrickBot is a modular malware that allows for the deployment of additional capabilities, such as data harvesting, reconnaissance of the victim’s local network configuration and lateral movement without exploitation.
  • Anchor uses a DNS-based command-and-control (C2) protocol that allows connections to a remote C2 server for tasking.
  • MagneticScraper is used for stealing credit card data in both Track 1 and Track 2 formats from PoS systems.
  • Ryuk is a variant of the Hermes ransomware that has been tailored to execute in an enterprise environment. It uses RSA-2048 and AES-256 for encrypting files

Targeted Nations

  • Flag Icon of the country Australia

    Australia

  • Flag Icon of the country Belgium

    Belgium

  • Flag Icon of the country Canada

    Canada

  • Flag Icon of the country Dominican Republic

    Dominican Republic

  • Flag Icon of the country Europe

    Europe

  • Flag Icon of the country France

    France

  • Flag Icon of the country Germany

    Germany

  • Flag Icon of the country Italy

    Italy

  • Flag Icon of the country Japan

    Japan

  • Flag Icon of the country Mexico

    Mexico

  • Flag Icon of the country Netherlands

    Netherlands

  • Flag Icon of the country New Zealand

    New Zealand

  • Flag Icon of the country Norway

    Norway

  • Flag Icon of the country Singapore

    Singapore

  • Flag Icon of the country Spain

    Spain

  • Flag Icon of the country Switzerland

    Switzerland

  • Flag Icon of the country Taiwan

    Taiwan

  • Flag Icon of the country United Kingdom

    United Kingdom

  • Flag Icon of the country United States

    United States

Artwork

Adversary: Wizard Spider - Threat Actor

Crowdstrike Wizard Spider

I have read and accept the terms and conditions

Download
Explore Next Adversary

Terms and conditions

In order to download the adversary artwork, we kindly request you to accept our terms and conditions displayed below.

This image (“artwork”), is the intellectual property of CrowdStrike, Inc. and its affiliates and licensors (collectively, “us” or “we”) and may include other marks, trademarks, copyrighted materials, and other intellectual property (“assets”) that belong t o us, including, without limitation, CrowdStrike, the CrowdStrike logo, and CrowdStrike Falcon. We retain all right, title and interest in and to the artwork and all assets included therein. This artwork is offered to you as a convenience for your lawful a nd non-commercial use, solely as authorized by us, and subject to your compliance with these terms and conditions (“terms”) and any other guidelines or specifications that we may provide from time to time. We reserve the right to change these terms at any time without prior notice.

You should periodically check the latest information posted herein to be sure that you are in compliance. By downloading the artwork, you attest that you are at least 18 years of age and agree to the following terms, which const itute the sole and entire agreement between you and us with respect to the artwork. We reserve all rights not expressly granted to you herein. You may not use or display the artwork in any way: (i) that violates the rights of any person or entity or that may give rise to civil or criminal liability under laws or regulations applicable to you, another user, and/or CrowdStrike; (ii) that is defamatory, obscene, indecent, abusive, harassing, violent, hateful, inflammatory or otherwise objectionable; (iii) tha t is false, deceptive, misleading or fraudulent, including but not limited to: (a) any attempt to impersonate any person or entity, including any other user, CrowdStrike or a CrowdStrike employee; (b) any attempt to misrepresent your identity or affiliation with any person or organization; or (iv) for the purposes of recruiting, advertising, solicitation or commercial activities of any kind without our express written consent.

THE ARTWORK IS PROVIDED TO YOU BY CROWDSTRIKE ON AN “AS IS” AND “AS AVAILABLE” BA SIS, WITHOUT ANY WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED. EXCEPT TO THE EXTENT THAT A DISCLAIMER OF LIABILITY IS PROHIBITED UNDER APPLICABLE LAW, IN NO EVENT WILL CROWDSTRIKE, ITS AFFILIATES AND ITS LICENSORS, EMPLOYEES, AGENTS, OFFICERS AND DIRE CTORS BE LIABLE FOR DAMAGES OF ANY KIND, UNDER ANY LEGAL THEORY, ARISING OUT OF OR IN CONNECTION WITH YOUR USE, OR INABILITY TO USE, THE ARTWORK.