Uptime Hamster: 10d 12h 30mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza WIZARD SPIDER

WIZARD SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: DEV-0193, DEV-0237, FIN12, GOLD BLACKBURN, Periwinkle Tempest, Pistachio Tempest, Storm-0193, Storm-0230, TEMP.MixMaster, Trickbot LLC, UNC2053, IcedID (BokBot), está relacionado con actividades de Financial Crime, figuran TA542, Mealybug, Emotet, Criminal, TA542
Ver en IntelTracker → APTTrail →
WIZARD SPIDER is a Russia-based, financially motivated cybercrime group that emerged around September 2016, initially known for developing and distributing the TrickBot banking trojan. The group subsequently evolved its operations around 2018 to focus on "Big Game Hunting" ransomware attacks, notably with Ryuk and later Conti, adopting an affiliate-based Ransomware-as-a-Service (RaaS) model by 2020. Assessed with high confidence to be of Russian origin, WIZARD SPIDER's primary motivation is financial gain through extortion. What sets this group apart is its industrialization of ransomware operations, operating with a cartel-like structure and a rapid adaptation to evolving cyber defense landscapes, including the development of unique espionage software named Sidoh. The group operates under numerous aliases across the threat intelligence community, including FIN12, GOLD BLACKBURN, Periwinkle Tempest, Pistachio Tempest, UNC1878, TEMP.MixMaster, DEV-0193, DEV-0237, Storm-0193, Storm-0230,

Aliases del actor

DEV-0193DEV-0237FIN12GOLD BLACKBURNPeriwinkle TempestPistachio TempestStorm-0193Storm-0230TEMP.MixMasterTrickbot LLCUNC2053IcedID (BokBot)está relacionado con actividades de Financial Crimefiguran TA542MealybugEmotetCriminalTA542otros

Actores similares

Cinnamon Tempestactor · 1Mustard Tempestapt · 1Phlox Tempestapt · 0Velvet Tempestapt · 0Operation SLOW#TEMPESTapt · 0wizard-spideractor · 1Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1
Motivacion