WizardSpider
Wizard Spider is a criminal threat actor associated in the provided content with use of Conti ransomware. The content links the group to the 2021 ransomware attack on Ireland's Health Service Executive (HSE), which caused months of disruption and millions in damage. According to the cited PWC report, the intrusion began on 16 March 2021 when a user opened a malicious Microsoft Excel attachment delivered via phishing email. PWC attributed the intrusion to Wizard Spider, stated the attackers likely exploited an unpatched known vulnerability to gain access to HSE's Active Directory domain, and reported that the group maintained access for roughly two months before deploying the final Conti v3 payload on 14 May 2021. The content also states that HSE personnel had observed Wizard Spider activity before detonation and that antivirus detections included Cobalt Strike and Mimikatz. During the intrusion, the group reportedly compromised systems in multiple hospitals. The content further describes leaked internal chats from the Russia-affiliated Conti ransomware gang and notes that Wizard Spider used Conti ransomware in the HSE attack. Separately, Sophos reported a case involving a Canadian healthcare organization where Conti and the Karma ransomware gang both gained access via the ProxyShell exploit; in that incident, Conti encrypted much of the organization's data and dropped a batch script to disable Windows Defender before deploying its ransomware payload. Alias directly provided in the content: wizardspider.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Health Care Equipment & Services
- Government & Administration
Where they target
Geographies tied to known operations.
- 🇮🇪 Ireland
Tradecraft
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
3 malware families attributed to this actor across reporting.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Criminal crew identified as using Conti ransomware in the attack on Ireland's state-run health service.
Conducted the ransomware intrusion against Ireland's Health Service Executive, gaining initial access via a phishing email attachment, maintaining access for roughly two months, deploying Cobalt Strike and Mimikatz, moving across multiple hospitals, and ultimately detonating Conti v3 ransomware.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.