Threat group.View on attack.mitre.org
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne. |
| T1003.002 Security Account Manager |
Wizard Spider has acquired credentials from the SAM/SECURITY registry hives. |
| T1003.003 NTDS |
Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil. |
| T1005 Data from Local System |
Wizard Spider has collected data from a compromised host prior to exfiltration. |
| T1016 System Network Configuration Discovery |
Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory. |
| T1018 Remote System Discovery |
Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
| T1021 Remote Services |
Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares. |
| T1021.001 Remote Desktop Protocol |
Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively. |
| T1021.002 SMB/Windows Admin Shares |
Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement. |
| T1021.006 Windows Remote Management |
Wizard Spider has used Window Remote Management to move laterally through a victim network. |
| T1027.010 Command Obfuscation |
Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands. |
| T1033 System Owner/User Discovery |
Wizard Spider has used "whoami" to identify the local user and their privileges. |
| T1036.004 Masquerade Task or Service |
Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries. |
| T1041 Exfiltration Over C2 Channel |
Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels. |
| T1047 Windows Management Instrumentation |
Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.