Wizard Spider is a criminal ransomware threat actor associated in the provided content with the Conti and Ryuk ransomware families. The content describes Wizard Spider as the group behind Conti operations, including the 2021 ransomware attack against Ireland’s Health Service Executive (HSE), where the intrusion reportedly began with a phishing email carrying a malicious Microsoft Excel attachment, involved roughly two months of attacker access, likely included exploitation of an unpatched known vulnerability to reach the Active Directory domain, and culminated in deployment of the Conti v3 payload. The content also states that antivirus detections identified Cobalt Strike and Mimikatz on the patient-zero workstation before detonation, and that Wizard Spider activity was observed across multiple hospitals before the final ransomware deployment. Separately, the content associates Wizard Spider with use of SystemBC, a malware family used as a proxy malware, bot, backdoor, and RAT, often alongside Cobalt Strike and during reconnaissance, lateral movement, and malware deployment. The content further states that Akira maintains a close relationship with Conti, that parts of Akira ransomware code are an evolution or another version of Conti code used by Wizard Spider, and that the security community often considers Akira a subgroup of Wizard Spider. The content also describes Conti as Russia-affiliated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.