All actors

Wizard Spider

Also reported as Periwinkle Tempest, DEV-0193, UNC1878, TEMP.MixMaster, FIN12 and 15 other names. Linked to Russia by four sources.

Reports
1,158
Last reported
Known CVEs
499
Techniques in ATT&CK
64
Origin
Russia
ID
G0102
Merge evidence
43 alias matches

Reports per quarter

  1. 2015 Q4: 1 report
  2. 2016 Q1: no reports
  3. 2016 Q2: no reports
  4. 2016 Q3: no reports
  5. 2016 Q4: 5 reports
  6. 2017 Q1: no reports
  7. 2017 Q2: 5 reports
  8. 2017 Q3: 2 reports
  9. 2017 Q4: 1 report
  10. 2018 Q1: 5 reports
  11. 2018 Q2: 3 reports
  12. 2018 Q3: 3 reports
  13. 2018 Q4: 12 reports
  14. 2019 Q1: 21 reports
  15. 2019 Q2: 16 reports
  16. 2019 Q3: 8 reports
  17. 2019 Q4: 23 reports
  18. 2020 Q1: 39 reports
  19. 2020 Q2: 31 reports
  20. 2020 Q3: 33 reports
  21. 2020 Q4: 92 reports
  22. 2021 Q1: 71 reports
  23. 2021 Q2: 81 reports
  24. 2021 Q3: 96 reports
  25. 2021 Q4: 87 reports
  26. 2022 Q1: 126 reports
  27. 2022 Q2: 115 reports
  28. 2022 Q3: 59 reports
  29. 2022 Q4: 22 reports
  30. 2023 Q1: 21 reports
  31. 2023 Q2: 12 reports
  32. 2023 Q3: 19 reports
  33. 2023 Q4: 18 reports
  34. 2024 Q1: 7 reports
  35. 2024 Q2: 13 reports
  36. 2024 Q3: 20 reports
  37. 2024 Q4: 13 reports
  38. 2025 Q1: 8 reports
  39. 2025 Q2: 9 reports
  40. 2025 Q3: 7 reports
  41. 2025 Q4: 4 reports
  42. 2026 Q1: 5 reports
  43. 2026 Q2: 45 reports
Dated reports, 2015 Q4 to 2026 Q2.

Techniques seen in the last two years

Show all 276 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 14 techniques Show fewer

CVEs named in reports

Show all 499 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. ISFB (Malware Family)

    date ORKL added it fromORKL

Show all 1,158 reports Show fewer
  1. BazarBackdoor (Malware Family)

    date ORKL added it fromORKL

  2. Conti (Malware Family)

    date ORKL added it fromORKL

  3. IcedID (Malware Family)

    date ORKL added it fromORKL

  4. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  5. Ryuk (Malware Family)

    date ORKL added it fromORKL

  6. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  7. Hive0137 on AI journey

    Malpedia library date fromORKL

  8. The DPRK delicate sound of cyber

    date in the title fromORKL

  9. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  10. Bumblebee Malware Loader- Threat Analysis

    date in the title fromORKL

  11. RedSense

    Malpedia library date fromORKL

  12. BumbleBee Roasts Its Way to Domain Admin

    date in the title fromORKL

  13. RedSense

    Malpedia library date fromORKL

  14. CERT-UA

    Malpedia library date fromORKL

  15. CERT-UA

    Malpedia library date fromORKL

  16. Hive ransomware gets upgrades in Rust

    date in the title fromORKL

  17. The many lives of BlackCat ransomware

    date in the title fromORKL

  18. RedSense

    Malpedia library date fromORKL

  19. eset_threat_report_t12022

    file creation date fromORKL

  20. Malware Analysis- Trickbot

    date in the title fromORKL

  21. RedSense

    Malpedia library date fromORKL

  22. RedSense

    Malpedia library date fromORKL

  23. Network Footprints of Gamaredon Group

    date in the title fromORKL

  24. Russian cyber attack campaigns and actors.pdf

    file creation date fromORKL

  25. ransomware-chats.pdf?1651576098

    Malpedia library date fromORKL

  26. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  27. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  28. Russian State-Sponsored and Criminal Cyber .pdf

    file creation date fromORKL

  29. RedSense

    Malpedia library date fromORKL

  30. Sandworm- A tale of disruption told anew

    date in the title fromORKL

  31. Exposing initial access broker with ties to Conti

    date in the title fromORKL

  32. What Wicked Webs We Un-weave

    date in the title fromORKL

  33. CERT-UA

    Malpedia library date fromORKL

  34. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  35. 2021trends.pdf

    Malpedia library date fromORKL

  36. RedSense

    Malpedia library date fromORKL

  37. RedSense

    Malpedia library date fromORKL

  38. Report2022GTR

    file creation date fromORKL

  39. eset_threat_report_t32021

    file creation date fromORKL

  40. ALPHV ransomware gang analysis

    date in the title fromORKL

  41. Kraken the Code on Prometheus

    date in the title fromORKL

  42. RedSense

    Malpedia library date fromORKL

  43. Diavol Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  44. Diavol Ransomware

    date in the title fromORKL

  45. Conti Ransomware

    Malpedia library date fromORKL

  46. FINDING BEACONS IN THE DARK 1650728751599

    Malpedia library date BlackBerry fromORKLCCS '25 data

  47. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  48. RedSense

    Malpedia library date fromORKL

  49. eset_threat_report_t22021

    file creation date fromORKL

  50. Falcon OverWatch Hunts Down Adversaries Where They Hide

    date in the title fromORKL

  51. Report2021ThreatHunting

    file creation date fromORKL

  52. Sidoh- WIZARD SPIDER’s Mysterious Exfiltration Tool

    date in the title fromORKL

  53. Cobalt Strike, a Defender’s Guide

    date in the title fromORKL

  54. An insider insights into Conti operations – Part one

    date in the title fromORKL

  55. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  56. Detecting Trickbot with Splunk

    date in the title fromORKL

  57. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  58. Is Diavol Ransomware Connected to Wizard Spider-

    date in the title fromORKL

  59. Diavol - A New Ransomware Used By Wizard Spider-

    date in the title fromORKL

  60. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  61. CTIR_casestudy_2.pdf

    file creation date fromORKL

  62. CTIR_casestudy_1.pdf

    file creation date fromORKL

  63. Intel 471

    Malpedia library date fromORKL

  64. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  65. 2021-Threat-Detection-Report

    file creation date fromORKL

  66. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  67. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  68. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  69. Nice to meet you too My name is Ryuk

    date in the title fromORKL

  70. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  71. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  72. BazarLoader’s Elaborate Flower Shop Lure

    date in the title fromORKL

  73. Trickbot Still Alive and Well

    date in the title fromORKL

  74. Collaboration Between FIN7 and the RYUK Group

    date in the CCS '25 data Truesec fromORKLCCS '25 data

  75. Russian cyber attack campaigns and actors

    date in the title fromORKL

  76. Analyzing Network Infrastructure as Composite Objects

    date in the title fromORKL

  77. Ryuk Speed Run, 2 Hours to Ransom

    date in the title fromORKL

  78. SCYTHE Library: #ThreatThursday - Ryuk

    Malpedia library date fromORKL

  79. UNC 1878 Indicators from Threatconnect

    date in the title fromORKL

  80. Building wave of ransomware attacks strike U.S. hospitals

    date in the title fromORKL

  81. UNC1878 Indicators

    Malpedia library date fromORKL

  82. UNC1878 indicators

    date in the title fromORKL

  83. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  84. WIZARD SPIDER Update- Resilient, Reactive and Resolute

    date in the title fromORKL

  85. Tracing fresh Ryuk campaigns itw

    Malpedia library date fromORKL

  86. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  87. wp-spark-state-of-ransomware.pdf

    file creation date fromORKL

  88. Russian Cyber Attack Campaigns and Actors - Threat Research

    file creation date fromORKL

  89. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  90. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  91. They Come in the Night- Ransomware Deployment Trends

    date in the title fromORKL

  92. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  93. 2020_State-of-Malware-Report.pdf

    Malpedia library date fromORKL

  94. Forensics Report True Hedge

    Malpedia library date fromORKL

  95. Hunting for Ransomware

    date in the title fromORKL

  96. Threat spotlight- the curious case of Ryuk ransomware

    date in the title fromORKL

  97. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  98. TrickBot Modifications Target U.S. Mobile Users

    date in the title fromORKL

  99. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date ThaiCERT fromORKL

  100. Hunting and detecting Cobalt Strike

    date in the title fromORKL

  101. Threat Group Cards: A Threat Actor Encyclopedia

    file creation date Martijn van der Heide fromORKL

  102. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  103. Report2019GlobalThreatReport

    file creation date fromORKL

  104. CrowdStrike_GTR_2019.pdf

    file creation date fromORKL

  105. Informe_Evoluci%C3%B3n_Trickbot.pdf

    Malpedia library date fromORKL

  106. TrickBot Banker Insights | NETSCOUT

    Malpedia library date fromORKL

Newest first. Details opens the report in Explore.