Cyber Resilience

Threat actor · all actors

Indrik SpiderG0119 state

🇷🇺 RU

aka Indrik Spider, Evil Corp, Manatee Tempest, DEV-0243, UNC2165, GOLD DRAKE

Last updated: 2026-08-22

1attributed CVEs
47ATT&CK techniques
1.2IDF score (tooling uniqueness)
0exclusive CVEs
2026years active

About this actor

INDRIK SPIDER is a sophisticated eCrime group that has been operating Dridex since June 2014. In 2015 and 2016, Dridex was one of the most prolific eCrime banking trojans on the market and, since 2014, those efforts are thought to have netted INDRIK SPIDER millions of dollars in criminal profits. Throughout its years of operation, Dridex has received multiple updates with new modules developed and new anti-analysis features added to the malware. In August 2017, a new ransomware variant identified as BitPaymer was reported to have ransomed the U.K.’s National Health Service (NHS), with a high ransom demand of 53 BTC (approximately $200,000 USD). The targeting of an organization rather than individuals, and the high ransom demands, made BitPaymer stand out from other contemporary ransomware at the time. Though the encryption and ransom functionality of BitPaymer was not technically sophisticated, the malware contained multiple anti-analysis features that overlapped with Dridex. Later technical analysis of BitPaymer indicated that it had been developed by INDRIK SPIDER, suggesting the group had expanded its criminal operation to include ransomware as a monetization strategy.

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0119

Microsoftweather-system names

Manatee Tempest

CrowdStrikenation-animal names

Indrik Spider

MandiantUNC uncategorised cluster

UNC2165

Secureworkscolour-metal names

GOLD DRAKE

Unclassifiedno scheme matched

Evil CorpDEV-0243

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 47 ATT&CK techniques on file.
Named victims
1 extracted from reporting.

Thin data: Only one named victim is on file.

See how actor data is built for the full pipeline.

Activity timeline

Profile

CVERiskCVSSEPSSPublishedProducts
CVE-2026-20929 5.97.50.01162026-01-13see CVE

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-431 / 4766%
AC-628 / 4760%
CM-628 / 4760%
AC-327 / 4757%
AC-226 / 4755%
CM-224 / 4751%
AC-520 / 4743%
IA-220 / 4743%
CA-719 / 4740%
CM-719 / 4740%
SI-719 / 4740%
CM-518 / 4738%
SI-318 / 4738%
IA-515 / 4732%
AC-413 / 4728%

Co-occurring actors

Similar actors

Overlapping CVEs