Cyber Resilience

Threat actor · all actors

Wizard SpiderG0102 state

🇷🇺 RU

aka Wizard Spider, UNC1878, TEMP.MixMaster, Grim Spider, FIN12, GOLD BLACKBURN, ITG23, Periwinkle Tempest, DEV-0193, Pistachio Tempest, DEV-0237, GOLD ULRICK, Storm-0193, Trickbot LLC, UNC2053, Storm-0230

Last updated: 2026-08-22

1attributed CVEs
92ATT&CK techniques
1.2IDF score (tooling uniqueness)
0exclusive CVEs
2026years active

About this actor

GRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER, a criminal enterprise of which GRIM SPIDER appears to be a cell. The WIZARD SPIDER threat group, known as the Russia-based operator of the TrickBot banking malware, had focused primarily on wire fraud in the past. Similar to Samas and BitPaymer, Ryuk is specifically used to target enterprise environments. Code comparison between versions of Ryuk and Hermes ransomware indicates that Ryuk was derived from the Hermes source code and has been under steady development since its release. Hermes is commodity ransomware that has been observed for sale on forums and used by multiple threat actors. However, Ryuk is only used by GRIM SPIDER and, unlike Hermes, Ryuk has only been used to target enterprise environments. Since Ryuk’s appearance in August, the threat actors operating it have netted over 705.80 BTC across 52 transactions for a total current value of $3,701,893.98 USD. Grim Spider is reportedly associated with Lunar Spider and Wizard Spider.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0102

Microsoftweather-system names

Periwinkle TempestPistachio TempestStorm-0193Storm-0230

CrowdStrikenation-animal names

Wizard SpiderGrim Spider

MandiantUNC uncategorised cluster

UNC1878UNC2053

MandiantFIN financially-motivated

FIN12

MandiantTEMP temporary cluster

TEMP.MixMaster

Secureworkscolour-metal names

GOLD BLACKBURNGOLD ULRICK

Unclassifiedno scheme matched

ITG23DEV-0193DEV-0237Trickbot LLC

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 92 ATT&CK techniques on file.
Named victims
None on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2026-20929 5.97.50.01162026-01-13see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-468 / 9274%
CM-661 / 9266%
AC-352 / 9257%
AC-651 / 9255%
AC-248 / 9252%
CM-248 / 9252%
CM-745 / 9249%
SI-342 / 9246%
CA-740 / 9243%
AC-538 / 9241%
IA-238 / 9241%
CM-537 / 9240%
SC-733 / 9236%
SI-732 / 9235%
AC-430 / 9233%

Co-occurring actors

Similar actors

Similar TTPs

Overlapping CVEs