Uptime Hamster: 21d 9h 5mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza WIZARD SPIDER

WIZARD SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: DEV-0193, DEV-0237, FIN12, GOLD BLACKBURN, Periwinkle Tempest, Pistachio Tempest, Storm-0193, Storm-0230, TEMP.MixMaster, Trickbot LLC, UNC2053, TA542, Mealybug, Emotet, Criminal, otros, IcedID (BokBot), está relacionado con actividades de Financial Crime
Ver en IntelTracker → APTTrail →
WIZARD SPIDER is a Russia-based, financially motivated cybercrime group that emerged around September 2016, initially known for developing and distributing the TrickBot banking trojan. The group subsequently evolved its operations around 2018 to focus on "Big Game Hunting" ransomware attacks, notably with Ryuk and later Conti, adopting an affiliate-based Ransomware-as-a-Service (RaaS) model by 2020. Assessed with high confidence to be of Russian origin, WIZARD SPIDER's primary motivation is financial gain through extortion. What sets this group apart is its industrialization of ransomware operations, operating with a cartel-like structure and a rapid adaptation to evolving cyber defense landscapes, including the development of unique espionage software named Sidoh. The group operates under numerous aliases across the threat intelligence community, including FIN12, GOLD BLACKBURN, Periwinkle Tempest, Pistachio Tempest, UNC1878, TEMP.MixMaster, DEV-0193, DEV-0237, Storm-0193, Storm-0230,

Aliases del actor

DEV-0193DEV-0237FIN12GOLD BLACKBURNPeriwinkle TempestPistachio TempestStorm-0193Storm-0230TEMP.MixMasterTrickbot LLCUNC2053TA542MealybugEmotetCriminalotrosIcedID (BokBot)está relacionado con actividades de Financial Crimefiguran TA542

Actores similares

Cinnamon Tempestthreat-actor · 1Mustard Tempestthreat-actor · 1Phlox Tempestapt · 0Velvet Tempestapt · 0Operation SLOW#TEMPESTapt · 0wizard-spideractor · 1Scattered Spiderthreat-actor · 2doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1
Motivacion