Threat actor · all actors
Wizard SpiderG0102 state
🇷🇺 RU
aka Wizard Spider, UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, DEV-0237, GOLD ULRICK, Storm-0193, Trickbot LLC, UNC2053, Storm-0230
Last updated: 2026-08-22
About this actor
GRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER, a criminal enterprise of which GRIM SPIDER appears to be a cell. The WIZARD SPIDER threat group, known as the Russia-based operator of the TrickBot banking malware, had focused primarily on wire fraud in the past. Similar to Samas and BitPaymer, Ryuk is specifically used to target enterprise environments. Code comparison between versions of Ryuk and Hermes ransomware indicates that Ryuk was derived from the Hermes source code and has been under steady development since its release. Hermes is commodity ransomware that has been observed for sale on forums and used by multiple threat actors. However, Ryuk is only used by GRIM SPIDER and, unlike Hermes, Ryuk has only been used to target enterprise environments. Since Ryuk’s appearance in August, the threat actors operating it have netted over 705.80 BTC across 52 transactions for a total current value of $3,701,893.98 USD. Grim Spider is reportedly associated with Lunar Spider and Wizard Spider.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
MandiantFIN financially-motivated
MandiantTEMP temporary cluster
Secureworkscolour-metal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 92 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.002Security Account Manager ↗T1003.003NTDS ↗T1005Data from Local System ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.002SMB/Windows Admin Shares ↗T1021.006Windows Remote Management ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1041Exfiltration Over C2 Channel ↗T1047Windows Management Instrumentation ↗T1048Exfiltration Over Alternative Protocol ↗T1048.003Exfiltration Over Unencrypted Non-C2 Protocol ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1055Process Injection ↗T1055.001Dynamic-link Library Injection ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1082System Information Discovery ↗T1087Account Discovery ↗T1087.002Domain Account ↗T1105Ingress Tool Transfer ↗T1112Modify Registry ↗T1133External Remote Services ↗T1135Network Share Discovery ↗T1136Create Account ↗T1136.001Local Account ↗T1136.002Domain Account ↗T1197BITS Jobs ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1210Exploitation of Remote Services ↗T1218System Binary Proxy Execution ↗T1218.011Rundll32 ↗T1222File and Directory Permissions Modification ↗T1222.001Windows Permissions ↗T1489Service Stop ↗T1490Inhibit System Recovery ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1518.002Backup Software Discovery ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1547.004Winlogon Helper DLL ↗T1550Use Alternate Authentication Material ↗T1550.002Pass the Hash ↗T1552Unsecured Credentials ↗T1552.006Group Policy Preferences ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1555Credentials from Password Stores ↗T1555.004Windows Credential Manager ↗T1557Adversary-in-the-Middle ↗T1557.001Name Resolution Poisoning and SMB Relay ↗T1558Steal or Forge Kerberos Tickets ↗T1558.003Kerberoasting ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1569System Services ↗T1569.002Service Execution ↗T1570Lateral Tool Transfer ↗T1585Establish Accounts ↗T1585.002Email Accounts ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.003Code Signing Certificates ↗T1685Disable or Modify Tools ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 68 / 92 | 74% |
CM-6 | 61 / 92 | 66% |
AC-3 | 52 / 92 | 57% |
AC-6 | 51 / 92 | 55% |
AC-2 | 48 / 92 | 52% |
CM-2 | 48 / 92 | 52% |
CM-7 | 45 / 92 | 49% |
SI-3 | 42 / 92 | 46% |
CA-7 | 40 / 92 | 43% |
AC-5 | 38 / 92 | 41% |
IA-2 | 38 / 92 | 41% |
CM-5 | 37 / 92 | 40% |
SC-7 | 33 / 92 | 36% |
SI-7 | 32 / 92 | 35% |
AC-4 | 30 / 92 | 33% |
Co-occurring actors
- Ajax Security Team 1 shared CVEs
- APT29 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
- OilRig 1 shared CVEs
- Indrik Spider 1 shared CVEs
- Mustang Panda 1 shared CVEs
Similar actors
Similar TTPs
- FIN8 0.40
- APT32 0.38
- APT41 0.38
- Operation Wocao 0.36
- FIN6 0.36
Active in same years
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
- Ke3chang 1.00
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00