Indrik Spider, most widely known as Evil Corp, is a Russian financially motivated cybercrime organization associated with major banking-malware and targeted ransomware operations. It is also tracked as DEV-0243, GOLD DRAKE, Manatee Tempest, and UNC2165; Evil Corp and TA505 have also been used in industry reporting for overlapping Dridex, BitPaymer, Locky, and large-scale malware-spam activity. U.S. Treasury has alleged that Maksim Yakubets, Evil Corp’s leader, worked for the FSB and was assigned projects on behalf of the Russian state while the organization conducted financially motivated attacks. Evil Corp operated Dridex from 2014 and used Dridex infections to support targeted deployment of BitPaymer ransomware from late 2017. It was later attributed with high confidence to WastedLocker, and has used SocGholish fake-browser-update activity to obtain initial access and deliver follow-on tooling, including custom Cobalt Strike loaders. SocGholish activity abuses compromised legitimate websites and social-engineering lures to induce execution of malicious update packages, then profiles systems and retrieves secondary payloads. Indrik Spider has also used PowerShell Empire, PowerShell, command-shell and batch-script execution, downloaded additional tools after compromise, and searched local files for credentials to exfiltrate. WastedLocker operations targeted enterprise file servers, databases, virtual machines, cloud environments, and local, removable, shared, and remote storage. The ransomware used privilege-escalation and defense-evasion mechanisms, deleted shadow copies, established temporary service-based execution, and encrypted victim data. Available reporting did not show Evil Corp extensively using stolen-data publication or leak-site extortion in its WastedLocker activity. Victims were concentrated in North America, particularly the United States, with additional activity in Western Europe. Financial institutions and their customers have been a persistent target set for Dridex-enabled banking credential theft and fraud.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
27 malware families attributed to this actor across reporting.
22 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
VMware ESXi hypervisors joined to an Active Directory domain grant full administrative access by default to members of a domain group named "ESX Admins." Attackers create that group or add controlled accounts to it to gain administrative access.
ZDI identified nearly 1,000 malicious .lnk files abusing ZDI-CAN-25373 (aka ZDI-25-148), a vulnerability that allows attackers to execute hidden malicious commands on a victim’s machine by leveraging crafted shortcut files.
Les vecteurs d’attaque changent rapidement. Ainsi, le passage de la version 3 à la version 4 de Dridex début 2017 a été accompagné de l’ajout de la faille 0-day MS Word (CVE-2017-0199)... Faille permettant de dissimuler des instructions malveillantes dans un document sauvegardé au format .RTF.
the attackers initially accessed targeted organizations’ networks with ProxyShell, an exploit of vulnerabilities in Microsoft Exchange
GTIG identified UNC2165... leveraging CVE-2025-8088 to distribute malware in mid-July 2025.
249 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed only as an annotation associated with the detection.
Listed only in the detection's ATT&CK/actor annotations.
Indrik Spider appears only in the detection's annotations list.
Referenced as a Russia-based cybercrime organization whose alleged leader was said to have worked for the FSB while the group also conducted financially motivated attacks, illustrating blurred lines between Russian cybercrime and state-linked activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.