Evil Corp, also tracked as Indrik Spider, is a Russian cybercriminal threat actor associated with large-scale financial malware, initial access operations, ransomware, and money laundering activity. Widely used aliases include Indrik Spider, Gold Drake, Gold Prelude, DEV-0243, UNC2165, Manatee Tempest, Mustard Tempest, and in some reporting TA569 for activity tied to the SocGholish ecosystem. The group has longstanding associations with the Zeus and Dridex malware lineages and has also been linked to ransomware operations including WastedLocker, Hades, and related extortion activity. Evil Corp has historically targeted enterprises and organizations for financially motivated intrusion, credential theft, fraud, and ransomware deployment. The group is notable for operating across multiple stages of the intrusion lifecycle, including malware distribution, initial access, post-compromise reconnaissance, credential access, lateral enablement, and monetization. Reporting also links the actor to loader and traffic-distribution activity involving SocGholish, also known as FakeUpdates or GhoLoader, which is commonly delivered through compromised websites and fake browser update lures. SocGholish infections have been used to establish footholds that can support follow-on malware deployment, credential theft, and ransomware operations. The actor has used a broad tooling ecosystem over time, including banking trojans, loaders, remote access frameworks, and ransomware. Public reporting associates Evil Corp with malware and tooling such as Dridex, SocGholish, WastedLocker, ShadowCoil, and VIPERTUNNEL, as well as use of commercial or widely abused post-exploitation frameworks such as Cobalt Strike and NetSupport. In one documented cluster, VIPERTUNNEL was described as a Python-based backdoor establishing SOCKS5 proxy tunnels and sharing obfuscation characteristics with ShadowCoil, with infrastructure linked to UNC2165 and Evil Corp. Operationally, Evil Corp is known for adaptable tradecraft and for shifting malware branding, affiliate relationships, and payload choices to sustain access and monetization. The group has been connected in various reporting to overlapping criminal ecosystems and collaborations involving other major Russian-speaking cybercrime actors, including ties noted with Dridex operations, Conti-linked individuals, and other ransomware or loader ecosystems. Some reporting describes offshoots or evolutionary links between Evil Corp-associated activity and later ransomware brands such as DoppelPaymer and Grief. Evil Corp is sanctioned by the United States and has been described as having connections to the Russian state or government-affiliated individuals in some enforcement and intelligence reporting. High-confidence public reporting consistently characterizes the actor as a major Russian-speaking financially motivated cybercrime organization with a durable role in the broader ransomware-enablement and malware distribution ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
27 malware families attributed to this actor across reporting.
22 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
The vulnerability, identified as CVE-2024-37085, involves a domain group whose members are granted full administrative access to the ESXi hypervisor by default without proper validation... VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named “ESX Admins” to have full administrative access by default.
GTIG identified UNC2165... leveraging CVE-2025-8088 to distribute malware in mid-July 2025.
CVE-2026-41940, the cPanel authentication bypass, illustrates the opportunistic mass-exploitation pattern most clearly. What began as exploratory probing evolved into a multi-actor campaign combining ransomware deployment, website defacement, and — in at least one documented case — targeted cyber-espionage.
450 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware operations facilitated by Media Land LLC.
Referenced as the Russian cybercrime group tied to the SocGholish malware installer used via hacked websites.
Referenced as the threat group linked to the SocGholish/FakeUpdates/GhoLoader malware infrastructure disrupted earlier in the same Operation Endgame phase.
Linked to the SocGholish malware strain and known for large-scale cybercriminal activity involving Zeus and Dridex, as well as ransomware and money laundering operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.