Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]
Name | Description |
---|---|
UNC1878 | |
TEMP.MixMaster | |
Grim Spider |
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1087 | .002 | Account Discovery: Domain Account |
Wizard Spider has identified domain admins through the use of "net group ‘Domain admins’" commands.[7] |
Enterprise | T1557 | .001 | Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay |
Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning.[4] |
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols |
Wizard Spider has used HTTP for network communications.[6] |
Enterprise | T1547 | .001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
Wizard Spider has established persistence via the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and a shortcut within the startup folder.[2][4] |
.004 | Boot or Logon Autostart Execution: Winlogon Helper DLL |
Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon.[4] |
||
Enterprise | T1059 | .001 | Command and Scripting Interpreter: PowerShell |
Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines.[6] It has also used PowerShell to execute commands and move laterally through a victim network.[2][4][8] |
.003 | Command and Scripting Interpreter: Windows Command Shell |
Wizard Spider has used cmd.exe to execute commands on a victim's machine.[7] |
||
Enterprise | T1543 | .003 | Create or Modify System Process: Windows Service |
Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence.[6] |
Enterprise | T1074 | Data Staged |
Wizard Spider has collected and staged credentials and network enumeration information, using the networkdll and psfin TrickBot modules.[6] |
|
Enterprise | T1048 | .003 | Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol |
Wizard Spider has exfiltrated victim information using FTP.[7][9] |
Enterprise | T1041 | Exfiltration Over C2 Channel |
Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.[6] |
|
Enterprise | T1210 | Exploitation of Remote Services |
Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities.[4][7][10] |
|
Enterprise | T1133 | External Remote Services |
Wizard Spider has accessed victim networks by using stolen credentials to access the corporate VPN infrastructure.[4] |
|
Enterprise | T1222 | .001 | File and Directory Permissions Modification: Windows File and Directory Permissions Modification |
Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders.[11] |
Enterprise | T1562 | .001 | Impair Defenses: Disable or Modify Tools |
Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.[2][4][7] |
Enterprise | T1070 | .004 | Indicator Removal on Host: File Deletion |
Wizard Spider has used file deletion to remove some modules and configurations from an infected host after use.[6] |
Enterprise | T1570 | Lateral Tool Transfer |
Wizard Spider has used stolen credentials to copy tools into the |
|
Enterprise | T1036 | .004 | Masquerading: Masquerade Task or Service |
Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf.[6] It has also used common document file names for other malware binaries.[4] |
Enterprise | T1112 | Modify Registry |
Wizard Spider has modified the Registry key |
|
Enterprise | T1135 | Network Share Discovery |
Wizard Spider has used the "net view" command to locate mapped network shares.[2] |
|
Enterprise | T1027 | Obfuscated Files or Information |
Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.[5][7] |
|
Enterprise | T1588 | .002 | Obtain Capabilities: Tool |
Wizard Spider has obtained and used publicly-available post-exploitation frameworks and tools like Metasploit, Empire, Mimikatz.[4] |
.003 | Obtain Capabilities: Code Signing Certificates |
Wizard Spider obtained a code signing certificate signed by Digicert for some of its malware.[9] |
||
Enterprise | T1003 | .002 | OS Credential Dumping: Security Account Manager |
Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.[4] |
.003 | OS Credential Dumping: NTDS |
Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database.[4] |
||
Enterprise | T1566 | .001 | Phishing: Spearphishing Attachment |
Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar.[6][8] |
.002 | Phishing: Spearphishing Link |
Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services.[2][9] |
||
Enterprise | T1055 | .001 | Process Injection: Dynamic-link Library Injection |
Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions.[2][9] |
Enterprise | T1021 | .001 | Remote Services: Remote Desktop Protocol |
Wizard Spider has used RDP for lateral movement.[6][2][9] |
.002 | Remote Services: SMB/Windows Admin Shares |
Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement.[9][7] |
||
.006 | Remote Services: Windows Remote Management |
Wizard Spider has used Window Remote Management to move laterally through a victim network.[2] |
||
Enterprise | T1018 | Remote System Discovery |
Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind and |
|
Enterprise | T1053 | .005 | Scheduled Task/Job: Scheduled Task |
Wizard Spider has used scheduled tasks establish persistence for TrickBot and other malware.[6][2][4][9] |
Enterprise | T1489 | Service Stop |
Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption.[7] |
|
Enterprise | T1518 | .001 | Software Discovery: Security Software Discovery |
Wizard Spider has used WMI to identify anti-virus products installed on a victim's machine.[7] |
Enterprise | T1558 | .003 | Steal or Forge Kerberos Tickets: Kerberoasting |
Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.[7][4][2][9] |
Enterprise | T1553 | .002 | Subvert Trust Controls: Code Signing |
Wizard Spider has used Digicert code-signing certificates for some of its malware.[9] |
Enterprise | T1082 | System Information Discovery |
Wizard Spider has used "systeminfo" and similar commands to acquire detailed configuration information of a victim machine.[7] |
|
Enterprise | T1016 | System Network Configuration Discovery |
Wizard Spider has used "ipconfig" to identify the network configuration of a victim machine.[11] |
|
Enterprise | T1033 | System Owner/User Discovery |
Wizard Spider has used "whoami" to identify the local user and their privileges.[11] |
|
Enterprise | T1569 | .002 | System Services: Service Execution |
Wizard Spider has used services.exe to execute scripts and executables during lateral movement within a victim network.[7][10] |
Enterprise | T1204 | .001 | User Execution: Malicious Link |
Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing.[2] |
.002 | User Execution: Malicious File |
Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar.[6][3] |
||
Enterprise | T1078 | Valid Accounts |
Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers.[6] |
|
.002 | Domain Accounts |
Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network.[4] |
||
Enterprise | T1047 | Windows Management Instrumentation |
Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally.[6][2][4][8] |