Grim Spider is an advanced persistent threat (APT) that has been identified by security researchers in recent years. It targets various industries, including government agencies and critical infrastructure organizations, with the goal of stealing sensitive information or gaining access to their networks for future exploitation. Grim Spider\'s tactics include spear-phishing emails, watering hole attacks, and social engineering techniques such as baiting. The group has been linked to various countries including China, Russia, Iran, North Korea, and others.
Techniques, tactics and practices:
Grim Spider\'s tactics include spear-phishing emails that contain malicious attachments or links to compromised websites. They also use watering hole attacks, which involve targeting specific organizations and injecting their own code into legitimate websites frequented by the intended targets. Additionally, Grim Spider employs social engineering techniques such as baiting, where they offer fake job opportunities or other enticing offers to lure unsuspecting victims into downloading malware-infected attachments or clicking on links that lead them to compromised websites.
GRIM SPIDER is a sophisticated eCrime group that has been
operating the Ryuk ransomware since August 2018, targeting large organizations
for a high-ransom return. This methodology, known as “big game hunting,”
signals a shift in operations for WIZARD SPIDER, a criminal enterprise of which
GRIM SPIDER appears to be a cell. The WIZARD SPIDER threat group, known as the
Russia-based operator of the TrickBot banking malware, had focused primarily on
wire fraud in the past. Similar to Samas and BitPaymer, Ryuk is specifically
used to target enterprise environments. Code comparison between versions of
Ryuk and Hermes ransomware indicates that Ryuk was derived from the Hermes
source code and has been under steady development since its release. Hermes is
commodity ransomware that has been observed for sale on forums and used by
multiple threat actors. However, Ryuk is only used by GRIM SPIDER and, unlike
Hermes, Ryuk has only been used to target enterprise environments. Since Ryuk’s
appearance in August, the threat actors operating it have netted over 705.80
BTC across 52 transactions for a total current value of $3,701,893.98 USD. Grim
Spider is reportedly associated with Lunar Spider and Wizard Spider.
Alternative Names
TEMP.MixMaster, G0102,
