Indrik Spider
G01190 reportsaliases · Indrik Spider · Evil Corp · Manatee Tempest · DEV-0243 · UNC2165
0
Reports
0
Techniques
0
Tactics
0
Countries
n/a
Hunt coverage
5
Aliases
Analyst assessment — key judgments
- No recorded activity: 0 report(s) in last 30d vs 0 prior (+0%).
- Assessment confidence: n/a.
Activity & trend
InactiveLast 30d: 0 vs 0 prior (+0%)
0
7d
0
30d
0
90d
0
All
0.0
Rpts/wk
Reporting timeline · 12 months
Vulnerabilities in this actor's reporting · 2
- CVE-2025-61882KEV1 rpt
- CVE-2025-8088KEV1 rpt
Overview
Analyst triage
Intelligence summary
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.(Citation: Crowdstrike Indrik November 2018)(Citation: Crowdstrike EvilCorp March 2021)(Citation: Treasury EvilCorp Dec 2019)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- No ATT&CK techniques associated yet.
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|