64
Techniques
22
Toolsets
3
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About Wizard Spider

Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.

View MITRE record ↗

Techniques by Tactic (64)
Toolsets (22)
🐛
Anchor S0504
Malware · Linux, Windows
🐛
Bazar S0534
Malware · Windows
🐛
Malware · Linux, macOS, Windows
🐛
Conti S0575
Malware · Windows
🐛
Diavol S0659
Malware · Windows
🐛
Dyre S0024
Malware · Windows
🐛
Emotet S0367
Malware · Windows
🐛
GrimAgent S0632
Malware · Windows
🐛
Ryuk S0446
Malware · Windows
🐛
SystemBC S9001
Malware · Linux, Windows
🐛
TrickBot S0266
Malware · Windows
🔧
AdFind S0552
Tool · Windows
🔧
BITSAdmin S0190
Tool · Windows
🔧
Tool · Windows
🔧
Empire S0363
Tool · Linux, macOS, Windows
🔧
LaZagne S0349
Tool · Linux, macOS, Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
Net S0039
Tool · Windows
🔧
Nltest S0359
Tool · Windows
🔧
Ping S0097
Tool
🔧
PsExec S0029
Tool · Windows
🔧
Rubeus S1071
Tool · Windows
CVEs Referenced (3 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
CVE-2017-0176View full details on NVD
↑