Evil Corp, also tracked as Indrik Spider, is a Russian financially motivated cybercrime organization associated with DEV-0243, Gold Drake, Manatee Tempest, and UNC2165. Industry reporting has also linked certain Dridex, BitPaymer, Locky, and large-scale malware-spam activity to Evil Corp or TA505. U.S. Treasury has sanctioned Evil Corp and stated that alleged leader Maksim Yakubets worked for the FSB on projects for the Russian state while the organization conducted financially motivated attacks. The group has operated Dridex since 2014, initially using it as a banking Trojan and modular loader for credential theft and fraud, then increasingly using Dridex-derived access for targeted ransomware operations. Evil Corp has been attributed with high confidence to WastedLocker and is associated with BitPaymer; it has also been linked in reporting to Hades, Phoenix, Grief, Macaw, and Entropy ransomware branding. Its ransomware operations have primarily targeted North American organizations, particularly U.S. enterprises, and have also affected Western European organizations. Evil Corp commonly gains access through social engineering, malware spam, and SocGholish fake browser or software-update lures delivered through compromised legitimate websites. SocGholish loaders profile hosts, conduct anti-analysis checks, and use Windows command interpreters or PowerShell to obtain subsequent payloads. Evil Corp has used PowerShell Empire historically and later used customized Cobalt Strike loaders, Gozi ISFB variants, and legitimate Windows administration tools for post-compromise activity. Observed behaviors include downloading additional tools, reconnaissance, searching local files for credentials and exfiltrating them, privilege escalation, lateral movement, security-tool evasion, modification of recovery mechanisms, and ransomware deployment across local, removable, shared, and remote storage. WastedLocker operations selectively prioritize high-value servers, virtual machines, cloud environments, backup-related systems, and revenue-generating services before encrypting victim data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
ZDI identified nearly 1,000 malicious .lnk files abusing ZDI-CAN-25373 (aka ZDI-25-148), a vulnerability that allows attackers to execute hidden malicious commands on a victim’s machine by leveraging crafted shortcut files.
Les vecteurs d’attaque changent rapidement. Ainsi, le passage de la version 3 à la version 4 de Dridex début 2017 a été accompagné de l’ajout de la faille 0-day MS Word (CVE-2017-0199)... Faille permettant de dissimuler des instructions malveillantes dans un document sauvegardé au format .RTF.
the attackers initially accessed targeted organizations’ networks with ProxyShell, an exploit of vulnerabilities in Microsoft Exchange
The vulnerability, identified as CVE-2024-37085, involves a domain group whose members are granted full administrative access to the ESXi hypervisor by default without proper validation... VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named “ESX Admins” to have full administrative access by default.
GTIG identified UNC2165... leveraging CVE-2025-8088 to distribute malware in mid-July 2025.
249 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Indrik Spider appears only in the detection's annotations list.
Referenced as a Russia-based cybercrime organization whose alleged leader was said to have worked for the FSB while the group also conducted financially motivated attacks, illustrating blurred lines between Russian cybercrime and state-linked activity.
Russian cybercrime organization cited as an example of the blurred boundary between financially motivated criminal activity and work performed on behalf of the Russian state/FSB.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.