ATT&CKGroupsWizard Spider

Wizard Spider

G0102

Threat group.View on attack.mitre.org

About this group

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.

Techniques used64

Procedure examples64

TechniqueProcedure example
T1003.001
LSASS Memory

Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne.

T1003.002
Security Account Manager

Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.

T1003.003
NTDS

Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.

T1005
Data from Local System

Wizard Spider has collected data from a compromised host prior to exfiltration.

T1016
System Network Configuration Discovery

Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory.

T1018
Remote System Discovery

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

T1021
Remote Services

Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares.

T1021.001
Remote Desktop Protocol

Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively.

T1021.002
SMB/Windows Admin Shares

Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement.

T1021.006
Windows Remote Management

Wizard Spider has used Window Remote Management to move laterally through a victim network.

T1027.010
Command Obfuscation

Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.

T1033
System Owner/User Discovery

Wizard Spider has used "whoami" to identify the local user and their privileges.

T1036.004
Masquerade Task or Service

Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries.

T1041
Exfiltration Over C2 Channel

Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.

T1047
Windows Management Instrumentation

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

View all 64 procedure examples

Software22

Campaigns0

None recorded.

References3

  1. CrowdStrike Ryuk January 2019 Open source
    Hanel, A. (2019, January 10). Big Game Hunting with Ryuk: Another Lucrative Targeted Ransomware. Retrieved May 12, 2020.
  2. CrowdStrike Wizard Spider October 2020 Open source
    Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021.
  3. DHS/CISA Ransomware Targeting Healthcare October 2020 Open source
    DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.