Uptime Hamster: 10d 6h 2mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza GRIM SPIDER

GRIM SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: GOLD ULRICK, Onslow o Dataresolution, figuran TA542, Mealybug, Emotet, Criminal, TA542, otros
Ver en IntelTracker → APTTrail →
GRIM SPIDER is a financially motivated cybercriminal group, operating as a distinct subgroup within the broader Russia-based WIZARD SPIDER enterprise, known for deploying the Ryuk ransomware since August 2018. This group specializes in 'big game hunting,' meticulously targeting large organizations with the capacity to pay substantial ransoms, a strategic shift from WIZARD SPIDER's earlier focus on wire fraud. While initially tracked as an independent entity, intelligence reporting in June 2019 indicated that Ryuk operations were integrated into the core WIZARD SPIDER group, leading to the deprecation of the GRIM SPIDER designation as a standalone actor by some security researchers. Their methodology is characterized by targeted, human-operated attacks rather than indiscriminate, automated campaigns, making them immediately distinguishable by their bespoke approach to high-value targets.

Aliases del actor

GOLD ULRICKOnslow o Dataresolutionfiguran TA542MealybugEmotetCriminalTA542otros

Actores similares

grim-spideractor · 1Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1
Tecnicas MITRE
T1486, T1078, T1003, T1071.001, T1569.002
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
20
Actualizado
Wed, 01 Ju

Sectores objetivo (SOCRadar)

Energy & Utilities ManufacturingInformation ServicesEducational ServicesHealthCare & Social AssistancePublic AdministrationNewspaper Publishers