Threat actor · all actors
Indrik SpiderG0119 state
🇷🇺 RU
aka Indrik Spider, Evil Corp, Manatee Tempest, DEV-0243, UNC2165, GOLD DRAKE
Last updated: 2026-08-22
About this actor
INDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime banking trojans on the market and, since 2014, those efforts are thought to have netted INDRIK SPIDER millions of dollars in criminal profits. Throughout its years of operation, Dridex has received multiple updates with new modules developed and new anti-analysis features added to the malware. In August 2017, a new ransomware variant identified as BitPaymer was reported to have ransomed the U.K.’s National Health Service (NHS), with a high ransom demand of 53 BTC (approximately $200,000 USD). The targeting of an organization rather than individuals, and the high ransom demands, made BitPaymer stand out from other contemporary ransomware at the time. Though the encryption and ransom functionality of BitPaymer was not technically sophisticated, the malware contained multiple anti-analysis features that overlapped with Dridex. Later technical analysis of BitPaymer indicated that it had been developed by INDRIK SPIDER, suggesting the group had expanded its criminal operation to include ransomware as a monetization strategy.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
Secureworkscolour-metal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 47 ATT&CK techniques on file.
- Named victims
- 1 extracted from reporting.
Thin data: Only one named victim is on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1007System Service Discovery ↗T1012Query Registry ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.004SSH ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1047Windows Management Instrumentation ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.007JavaScript ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1105Ingress Tool Transfer ↗T1112Modify Registry ↗T1136Create Account ↗T1136.001Local Account ↗T1204User Execution ↗T1204.002Malicious File ↗T1484Domain or Tenant Policy Modification ↗T1484.001Group Policy Modification ↗T1486Data Encrypted for Impact ↗T1489Service Stop ↗T1552Unsecured Credentials ↗T1552.001Credentials In Files ↗T1555Credentials from Password Stores ↗T1555.005Password Managers ↗T1558Steal or Forge Kerberos Tickets ↗T1558.003Kerberoasting ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1583Acquire Infrastructure ↗T1584Compromise Infrastructure ↗T1584.004Server ↗T1585Establish Accounts ↗T1585.002Email Accounts ↗T1587Develop Capabilities ↗T1587.001Malware ↗T1590Gather Victim Network Information ↗T1685Disable or Modify Tools ↗T1685.005Clear Windows Event Logs ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 31 / 47 | 66% |
AC-6 | 28 / 47 | 60% |
CM-6 | 28 / 47 | 60% |
AC-3 | 27 / 47 | 57% |
AC-2 | 26 / 47 | 55% |
CM-2 | 24 / 47 | 51% |
AC-5 | 20 / 47 | 43% |
IA-2 | 20 / 47 | 43% |
CA-7 | 19 / 47 | 40% |
CM-7 | 19 / 47 | 40% |
SI-7 | 19 / 47 | 40% |
CM-5 | 18 / 47 | 38% |
SI-3 | 18 / 47 | 38% |
IA-5 | 15 / 47 | 32% |
AC-4 | 13 / 47 | 28% |
Co-occurring actors
- Ajax Security Team 1 shared CVEs
- APT29 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
- OilRig 1 shared CVEs
- Mustang Panda 1 shared CVEs
- SolarWinds Compromise 1 shared CVEs
Similar actors
Similar TTPs
- Wizard Spider 0.28
- Operation Wocao 0.27
- Fox Kitten 0.26
- APT5 0.25
- SharePoint ToolShell Exploitation 0.25
Active in same years
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
- Ke3chang 1.00
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00