National Cyber Warfare Foundation (NCWF)

Indrik Spider


0 user ratings
2024-06-18 15:21:28
blscott

 - archive -- 

Indrik Spider

MITRE:  G0119

Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.

 Alternate names
Evil Corp, Manatee Tempest, DEV-0243,


The Indrik Spider is an advanced persistent threat that has been active since at least 2015, targeting government and military organizations in various countries including Russia, Ukraine, Belarus, and Kazakhstan. It uses a combination of social engineering tactics to gain access to sensitive information through phishing emails or by exploiting vulnerabilities on compromised systems. The Indrik Spider is believed to be linked to the Russian military intelligence agency GRU and has been responsible for stealing confidential documents related to military operations, political activities, and diplomatic relations between countries.

Techniques, tactics and practices:

The Indrik Spider is a highly sophisticated threat that employs various techniques to gain access to sensitive information. Some of these include:

1. Social engineering tactics - The APT uses phishing emails or other forms of deception to trick users into clicking on links, downloading attachments, or providing their login credentials. This allows the attackers to bypass traditional security measures and gain access to compromised systems.
2. Exploitation of vulnerabilities - Once inside a system, Indrik Spider exploits known vulnerabilities in software such as Microsoft Office, Adobe Flash Player, and Java to further its objectives. The APT also uses custom-made malware that can evade detection by antivirus programs.
3. Stealthy tactics - To avoid being detected, the Indrik Spider employs stealth techniques like using encrypted communication channels or hiding their activities within legitimate network traffic. They may also use multiple layers of


Alternate Group Names
658314bc-3bb8-48d2-913a-c528607b75c8, INDRIK SPIDER, 

Alternative Names
TA505, SectorJ04, Evil Corp, GOLD TAHOE, G0092, 



Comments
new comment
Nobody has commented yet. Will you be the first?


Primary Names
FIN7
 




This link is from a restricted area of the forums.
Forum



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.