Indrik Spider
Also reported as Manatee Tempest, Evil Corp, DEV-0243, UNC2165, INDRIK SPIDER and 8 other names. Linked to Russia by four sources.
Reports per quarter
Techniques seen in the last two years
- T1486 5 reports in ATT&CK
- T1021.001 4 reports in ATT&CK
- T1047 4 reports in ATT&CK
- T1071 4 reports reports only
- T1007 3 reports in ATT&CK
- T1020 3 reports reports only
- T1027 3 reports reports only
- T1053.005 3 reports reports only
- T1056.001 3 reports reports only
- T1059 3 reports reports only
Show all 243 techniques Show fewer
- T1098 3 reports reports only
- T1105 3 reports in ATT&CK
- T1112 3 reports in ATT&CK
- T1133 3 reports reports only
- T1574.001 3 reports reports only
- T1588.003 3 reports reports only
- T1003.001 2 reports in ATT&CK
- T1016 2 reports reports only
- T1018 2 reports in ATT&CK
- T1021 2 reports reports only
- T1021.004 2 reports in ATT&CK
- T1046 2 reports reports only
- T1049 2 reports reports only
- T1053 2 reports reports only
- T1057 2 reports reports only
- T1059.006 2 reports reports only
- T1059.007 2 reports in ATT&CK
- T1071.001 2 reports reports only
- T1078 2 reports in ATT&CK
- T1083 2 reports reports only
- T1087 2 reports reports only
- T1090 2 reports reports only
- T1135 2 reports reports only
- T1189 2 reports reports only
- T1190 2 reports reports only
- T1489 2 reports in ATT&CK
- T1490 2 reports reports only
- T1547.001 2 reports reports only
- T1572 2 reports reports only
- T0846 1 report reports only
- T1003 1 report reports only
- T1005 1 report reports only
- T1008 1 report reports only
- T1010 1 report reports only
- T1012 1 report in ATT&CK
- T1016.001 1 report reports only
- T1021.002 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1033 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1041 1 report reports only
- T1053.003 1 report reports only
- T1055 1 report reports only
- T1055.001 1 report reports only
- T1055.002 1 report reports only
- T1055.003 1 report reports only
- T1055.004 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1059.001 1 report in ATT&CK
- T1059.002 1 report reports only
- T1059.003 1 report in ATT&CK
- T1059.004 1 report reports only
- T1059.005 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1068 1 report reports only
- T1069 1 report reports only
- T1069.001 1 report reports only
- T1069.002 1 report reports only
- T1069.003 1 report reports only
- T1070 1 report reports only
- T1070.004 1 report reports only
- T1071.004 1 report reports only
- T1072 1 report reports only
- T1074 1 report reports only
- T1074.001 1 report in ATT&CK
- T1074.002 1 report reports only
- T1078.004 1 report reports only
- T1082 1 report reports only
- T1087.001 1 report reports only
- T1087.002 1 report reports only
- T1087.004 1 report reports only
- T1090.001 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1095 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1098.007 1 report reports only
- T1102 1 report reports only
- T1102.002 1 report reports only
- T1104 1 report reports only
- T1110 1 report reports only
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1119 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1124 1 report reports only
- T1125 1 report reports only
- T1129 1 report reports only
- T1132 1 report reports only
- T1132.001 1 report reports only
- T1134 1 report reports only
- T1134.001 1 report reports only
- T1136 1 report in ATT&CK
- T1136.001 1 report in ATT&CK
- T1136.002 1 report reports only
- T1137 1 report reports only
- T1137.006 1 report reports only
- T1140 1 report reports only
- T1195 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1203 1 report reports only
- T1204 1 report reports only
- T1204.001 1 report reports only
- T1204.002 1 report in ATT&CK
- T1210 1 report reports only
- T1212 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1217 1 report reports only
- T1218.010 1 report reports only
- T1219 1 report reports only
- T1482 1 report reports only
- T1484 1 report reports only
- T1484.001 1 report in ATT&CK
- T1485 1 report reports only
- T1491.002 1 report reports only
- T1496 1 report reports only
- T1497 1 report reports only
- T1497.001 1 report reports only
- T1505 1 report reports only
- T1505.003 1 report reports only
- T1505.004 1 report reports only
- T1518 1 report reports only
- T1518.001 1 report reports only
- T1529 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1543.003 1 report reports only
- T1543.004 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1546.015 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report reports only
- T1552 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1559 1 report reports only
- T1560 1 report reports only
- T1560.001 1 report reports only
- T1560.002 1 report reports only
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566 1 report reports only
- T1566.001 1 report reports only
- T1566.002 1 report reports only
- T1566.003 1 report reports only
- T1566.004 1 report reports only
- T1567 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report in ATT&CK
- T1569 1 report reports only
- T1569.002 1 report reports only
- T1570 1 report reports only
- T1571 1 report reports only
- T1573 1 report reports only
- T1573.001 1 report reports only
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583 1 report in ATT&CK
- T1583.003 1 report reports only
- T1584 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report in ATT&CK
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1595 1 report reports only
- T1595.002 1 report reports only
- T1598 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608 1 report reports only
- T1608.001 1 report reports only
- T1608.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report reports only
- T1608.005 1 report reports only
- T1608.006 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2010-0738 KEV ransomware
- CVE-2012-0507 KEV ransomware
- CVE-2012-5687
- CVE-2013-0074 KEV ransomware
- CVE-2013-2551 KEV ransomware
- CVE-2014-4404 KEV
- CVE-2014-6332 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0057
- CVE-2015-0313 KEV
- CVE-2015-1130 KEV
Show all 125 CVEs Show fewer
- CVE-2015-1635 KEV
- CVE-2015-2051 KEV
- CVE-2015-2419 KEV
- CVE-2016-0189 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11292 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-5638 KEV ransomware
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0752 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1054 KEV
- CVE-2020-11899 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-3529
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-38647 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-41379 KEV ransomware
- CVE-2021-44077 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1388 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-26134 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-21839 KEV
- CVE-2023-23397 KEV
- CVE-2023-27532 KEV ransomware
- CVE-2023-28252 KEV ransomware
- CVE-2023-34362 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-37085 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-9474 KEV ransomware
- CVE-2025-68613 KEV
- CVE-2026-1731 KEV ransomware
- CVE-2026-20127 KEV
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FAKEUPDATES (Malware Family)
-
Monty Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Monty Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
Indrik Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Indrik Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Hades (Malware Family)
Show all 268 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Meterpreter (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Babuk (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Dridex (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Zeus (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor WastedLocker (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FiveHands (Malware Family)
-
TA505, Graceful Spider, Gold Evergreen
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TA505, Graceful Spider, Gold Evergreen
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
artik.blue is for sale! Check it out on ExpiredDomains.com
The original link failed its last check. Original publisher Detailsfor artik.blue is for sale! Check it out on ExpiredDomains.com
-
Doppel Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Doppel Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
The original link failed its last check. Original publisher Detailsfor Untitled
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Schlag gegen international agierendes Netzwerk von Cyber-Kriminellen
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Schlag gegen international agierendes Netzwerk von Cyber-Kriminellen
-
Breaking the silence - Recent Truebot activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Breaking the silence - Recent Truebot activity
-
Microsoft links Raspberry Robin worm to Clop ransomware attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft links Raspberry Robin worm to Clop ransomware attacks
-
Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Raspberry Robin worm part of larger ecosystem facilitating pre-ransomware activity
-
Chapter 1 — From Gozi to ISFB- The history of a mythical malware family.
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chapter 1 — From Gozi to ISFB- The history of a mythical malware family.
-
Raspberry Robin’s Roshtyak- A Little Lesson in Trickery
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Raspberry Robin’s Roshtyak- A Little Lesson in Trickery
-
Raspberry Robin and Dridex- Two Birds of a Feather
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Raspberry Robin and Dridex- Two Birds of a Feather
-
Space Invaders- Cyber Threats That Are Out Of This World
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Space Invaders- Cyber Threats That Are Out Of This World
-
Microsoft Links Raspberry Robin USB Worm to Russian Evil Corp Hackers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Links Raspberry Robin USB Worm to Russian Evil Corp Hackers
-
Malware analysis with IDA/Radare2 - Basic Unpacking (Dridex first stage)
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Malware analysis with IDA/Radare2 - Basic Unpacking (Dridex first stage)
-
Ransomware as a Service- Behind the Scenes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware as a Service- Behind the Scenes
-
To HADES and Back- UNC2165 Shifts to LOCKBIT to Evade Sanctions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor To HADES and Back- UNC2165 Shifts to LOCKBIT to Evade Sanctions
-
SocGholish Campaigns and Initial Access Kit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor SocGholish Campaigns and Initial Access Kit
-
Ransomware-as-a-service- Understanding the cybercrime gig economy and how to protect yourself
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware-as-a-service- Understanding the cybercrime gig economy and how to protect yourself
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
The Ransomware Threat Landscape: What to Expect in 2022
The original link failed its last check. Original publisher Detailsfor The Ransomware Threat Landscape: What to Expect in 2022
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
Dridex bots deliver Entropy ransomware in recent attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dridex bots deliver Entropy ransomware in recent attacks
-
Sanctions Be Damned - From Dridex to Macaw, The Evolution of Evil Corp
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Sanctions Be Damned - From Dridex to Macaw, The Evolution of Evil Corp
-
Ransomware Becomes Deadlier, Conti Makes the Most Money
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Becomes Deadlier, Conti Makes the Most Money
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker malware analysis
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware Headliners- Dridex
-
Log4j vulnerability now used to install Dridex banking malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Log4j vulnerability now used to install Dridex banking malware
-
Tracking a P2P network related to TA505
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking a P2P network related to TA505
-
Evil Corp- 'My hunt for the world's most wanted hackers'
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evil Corp- 'My hunt for the world's most wanted hackers'
-
Diving into double extortion campaigns
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Diving into double extortion campaigns
-
Evil Corp demands $40 million in new Macaw ransomware attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evil Corp demands $40 million in new Macaw ransomware attacks
-
Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting TTPs Continue to Shift After DarkSide Pipeline Attack
-
Nationstate_ransomware_with_consecutive_endnotes.pdf
The original link failed its last check. Original publisher Detailsfor Nationstate_ransomware_with_consecutive_endnotes.pdf
-
Ransomware Gangs and the Name Game Distraction
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware Gangs and the Name Game Distraction
-
Ransomware gang breached CNA’s network via fake browser update
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ransomware gang breached CNA’s network via fake browser update
-
Inside the FBI, Russia, and Ukraine’s failed cybercrime investigation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside the FBI, Russia, and Ukraine’s failed cybercrime investigation
-
HADES ransomware operators continue attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HADES ransomware operators continue attacks
-
The First Step- Initial Access Leads to Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The First Step- Initial Access Leads to Ransomware
-
Hades Ransomware Operators Use Distinctive Tactics and Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hades Ransomware Operators Use Distinctive Tactics and Infrastructure
-
The blurry boundaries between nation-state actors and the cybercrime underground
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The blurry boundaries between nation-state actors and the cybercrime underground
-
The original link failed its last check. Original publisher Detailsfor Intel 471
-
New Evil Corp ransomware mimics PayloadBin gang to evade US sanctions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New Evil Corp ransomware mimics PayloadBin gang to evade US sanctions
-
Are The Notorious Cyber Criminals Evil Corp actually Russian Spies-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Are The Notorious Cyber Criminals Evil Corp actually Russian Spies-
-
APT35 ‘Charming Kitten' discovered in a pre-infected environment _ Blog _ Darktrace
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 ‘Charming Kitten' discovered in a pre-infected environment _ Blog _ Darktrace
-
APT35 ‘Charming Kitten' discovered in a pre-infected environment
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT35 ‘Charming Kitten' discovered in a pre-infected environment
-
How the Kremlin provides a safe harbor for ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How the Kremlin provides a safe harbor for ransomware
-
PaaS, or how hackers evade antivirus software
The original link failed its last check. Original publisher Detailsfor PaaS, or how hackers evade antivirus software
-
Evil Corp switches to Hades ransomware to evade sanctions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evil Corp switches to Hades ransomware to evade sanctions
-
Insurance giant CNA hit by new Phoenix CryptoLocker ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Insurance giant CNA hit by new Phoenix CryptoLocker ransomware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor SilverFish_TLPWHITE
-
INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor INDRIK SPIDER Supersedes WastedLocker with Hades Ransomware to Circumvent OFAC Sanctions
-
Q4 2020 Threat Report- A Quarterly Analysis of Cybersecurity Trends, Tactics and Themes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Q4 2020 Threat Report- A Quarterly Analysis of Cybersecurity Trends, Tactics and Themes
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dridex Malware Analysis
-
research.checkpoint.com-Stopping Serial Killer Catching the Next Strike
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor research.checkpoint.com-Stopping Serial Killer Catching the Next Strike
-
DRIDEX Stopping Serial Killer- Catching the Next Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DRIDEX Stopping Serial Killer- Catching the Next Strike
-
Wikipedia Page- Maksim Yakubets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Wikipedia Page- Maksim Yakubets
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Maksim Yakubets
-
What's behind the increase in ransomware attacks this year?
The original link failed its last check. Original publisher Detailsfor What's behind the increase in ransomware attacks this year?
-
What's behind the increase in ransomware attacks this year-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What's behind the increase in ransomware attacks this year-
-
Double Trouble- Ransomware with Data Leak Extortion, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 1
-
Double Trouble- Ransomware with Data Leak Extortion, Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Double Trouble- Ransomware with Data Leak Extortion, Part 1
-
Reverse Engineering Dridex and Automating IOC Extraction
The original link failed its last check. Original publisher Detailsfor Reverse Engineering Dridex and Automating IOC Extraction
-
MVISION Insights- Wastedlocker Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MVISION Insights- Wastedlocker Ransomware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-009
-
Dridex – From Word to Domain Dominance
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dridex – From Word to Domain Dominance
-
Threat Assessment- WastedLocker Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Assessment- WastedLocker Ransomware
-
Garmin outage caused by confirmed WastedLocker ransomware attack
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Garmin outage caused by confirmed WastedLocker ransomware attack
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-008
-
Threat spotlight- WastedLocker, customized ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat spotlight- WastedLocker, customized ransomware
-
WastedLocker_ Symantec Identifies Wave of Attacks Against U.S. Organizations _ Symantec Blogs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker_ Symantec Identifies Wave of Attacks Against U.S. Organizations _ Symantec Blogs
-
WastedLocker- Symantec Identifies Wave of Attacks Against U.S. Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker- Symantec Identifies Wave of Attacks Against U.S. Organizations
-
Russian hacker group Evil Corp targets US workers at home
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Russian hacker group Evil Corp targets US workers at home
-
WastedLocker- A New Ransomware Variant Developed By The Evil Corp Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker- A New Ransomware Variant Developed By The Evil Corp Group
-
WastedLocker_ A New Ransomware Variant Developed By The Evil Corp Group – NCC Group Research
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor WastedLocker_ A New Ransomware Variant Developed By The Evil Corp Group – NCC Group Research
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
Inside ‘Evil Corp,’ a $100M Cybercrime Menace
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Inside ‘Evil Corp,’ a $100M Cybercrime Menace
-
Anchor Project - The Deadly Planeswalker- How The TrickBot Group United High-Tech Crimeware & APT
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anchor Project - The Deadly Planeswalker- How The TrickBot Group United High-Tech Crimeware & APT
-
MORPHISEC DISCOVERS CCLEANER BACKDOOR SAVING MILLIONS OF AVAST USERS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor MORPHISEC DISCOVERS CCLEANER BACKDOOR SAVING MILLIONS OF AVAST USERS
-
Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Treasury Sanctions Evil Corp, the Russia-Based Cybercriminal Group Behind Dridex Malware
-
BitPaymer Source Code Fork- Meet DoppelPaymer Ransomware and Dridex 2.0
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BitPaymer Source Code Fork- Meet DoppelPaymer Ransomware and Dridex 2.0
-
Research, News, and Perspectives
The original link failed its last check. Original publisher Detailsfor Research, News, and Perspectives
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2019GlobalThreatReport
-
PINCHY SPIDER Affiliates Adopt “Big Game Hunting” Tactics to Distribute GandCrab Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PINCHY SPIDER Affiliates Adopt “Big Game Hunting” Tactics to Distribute GandCrab Ransomware
-
The original link failed its last check. Original publisher Detailsfor CrowdStrike_GTR_2019.pdf
-
Big Game Hunting with Ryuk- Another Lucrative Targeted Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting with Ryuk- Another Lucrative Targeted Ransomware
-
URSNIF, EMOTET, DRIDEX and BitPayme Linked by Loader
The original link failed its last check. Original publisher Detailsfor URSNIF, EMOTET, DRIDEX and BitPayme Linked by Loader
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Big Game Hunting- The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware
Newest first. Details opens the report in Explore.