Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne.4
group
Wizard Spider G0102
- Created
- 12 May 2020
- Last modified
- 31 July 2026
- Aliases
- Wizard Spider · UNC1878 · TEMP.MixMaster · Grim Spider · FIN12 · GOLD BLACKBURN · ITG23 · Periwinkle Tempest · DEV-0193 · Pistachio Tempest · DEV-0237
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0102
Wizard Spider has acquired credentials from the SAM/SECURITY registry hives.5
Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.67
Wizard Spider has collected data from a compromised host prior to exfiltration.8
Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet Get-ADComputer to collect IP address data from Active Directory.910
Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.111213141516
Standing G0102
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
91st percentile · 91% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
94th percentile · 94% of 176 ATT&CK groups have this many tactics spanned or fewer.
94th percentile · 94% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
65th percentile · 65% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0102
2398 distinct rules cover the 64 techniques recorded for this group. The 2747 technique-to-rule mappings resolve to 2398 distinct rules, because one rule can cover several techniques. 1532 Sigma · 866 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org