Indrik Spider is a Russia-based cybercriminal group that as been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware.[1][2][3]
Name | Description |
---|---|
Evil Corp |
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1059 | .001 | Command and Scripting Interpreter: PowerShell |
Indrik Spider has used PowerShell Empire for execution of malware.[1][4] |
.003 | Command and Scripting Interpreter: Windows Command Shell |
Indrik Spider has used batch scripts on victim's machines.[1] |
||
.007 | Command and Scripting Interpreter: JavaScript |
Indrik Spider has used malicious JavaScript files for several components of their attack.[4] |
||
Enterprise | T1584 | .004 | Compromise Infrastructure: Server |
Indrik Spider has served fake updates via legitimate websites that have been compromised.[1] |
Enterprise | T1136 | Create Account |
Indrik Spider used |
|
Enterprise | T1486 | Data Encrypted for Impact |
Indrik Spider has encrypted domain-controlled systems using BitPaymer.[1] |
|
Enterprise | T1074 | .001 | Data Staged: Local Data Staging |
Indrik Spider has stored collected date in a .tmp file.[4] |
Enterprise | T1484 | .001 | Domain Policy Modification: Group Policy Modification |
Indrik Spider has used Group Policy Objects to deploy batch scripts.[1] |
Enterprise | T1562 | .001 | Impair Defenses: Disable or Modify Tools |
Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring.[4] |
Enterprise | T1070 | .001 | Indicator Removal on Host: Clear Windows Event Logs |
Indrik Spider has used Cobalt Strike to empty log files.[4] |
Enterprise | T1105 | Ingress Tool Transfer |
Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.[1][4] |
|
Enterprise | T1036 | .005 | Masquerading: Match Legitimate Name or Location |
Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors.[1] |
Enterprise | T1003 | .001 | OS Credential Dumping: LSASS Memory |
Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump.[4] |
Enterprise | T1018 | Remote System Discovery |
Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database.[4] |
|
Enterprise | T1489 | Service Stop |
Indrik Spider has used PsExec to stop services prior to the execution of ransomware.[4] |
|
Enterprise | T1007 | System Service Discovery |
Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.[4] |
|
Enterprise | T1204 | .002 | User Execution: Malicious File |
Indrik Spider has attempted to get users to click on a malicious zipped file.[4] |
Enterprise | T1078 | .002 | Valid Accounts: Domain Accounts |
Indrik Spider has collected credentials from infected systems, including domain accounts.[1] |
Enterprise | T1047 | Windows Management Instrumentation |
Indrik Spider has used WMIC to execute commands on remote computers.[4] |