Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump.4
group
Indrik Spider G0119
- Created
- 6 January 2021
- Last modified
- 31 July 2026
- Aliases
- Indrik Spider · Evil Corp · Manatee Tempest · DEV-0243 · UNC2165
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0119
Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.5
Indrik Spider has used a service account to extract copies of the Security Registry hive.6
Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database.7
Indrik Spider has used RDP for lateral movement.8
Indrik Spider has used SSH for lateral movement.9
Standing G0119
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
69th percentile · 69% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
100th percentile · None of the 176 ATT&CK groups has more tactics spanned — the highest in the population.
76th percentile · 76% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
73rd percentile · 73% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0119
1576 distinct rules cover the 33 techniques recorded for this group. The 1717 technique-to-rule mappings resolve to 1576 distinct rules, because one rule can cover several techniques. 1027 Sigma · 549 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org