← Threat Actors / Russia / WIZARD SPIDER
DOSSIER // WIZARD-SPIDER

WIZARD SPIDER

▲ High Threat Russia
Primary Aliases: DEV-0193 DEV-0237 Grim Spider Periwinkle Tempest
Sponsor / State Affiliation Russian Federation
Primary Motivation Espionage / Financial
Active Timeline Unknown – Present
Confidence Rating 70% (Grounded)

Wizard Spider is reportedly associated with Grim Spider and Lunar Spider. The WIZARD SPIDER threat group is the Russia-based operator of the TrickBot banking malware. This group represents a growing criminal enterprise of which GRIM SPIDER appears to be a subset. The LUNAR SPIDER threat group is the Eastern European-based operator and developer of the commodity banking malware called BokBot (aka IcedID), which was first observed in April 2017. The BokBot malware provides LUNAR SPIDER affiliates with a variety of capabilities to enable credential theft and wire fraud, through the use of webinjects and a malware distribution function. GRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER, a criminal enterprise of which GRIM SPIDER appears to be a cell. The WIZARD SPIDER threat group, known as the Russia-based operator of the TrickBot banking malware, had focused primarily on wire fraud in the past.

⚔️ Weaponized CVE Matrix (0)

No specific weaponized CVEs currently mapped in the public baseline.

🎯 Target Sectors & Focus

Defense Financial Government Healthcare Telecommunications

🛡️ MITRE ATT&CK® Attack Lifecycle (64 TTPs)

📥 Download Navigator JSON

📰 Verified Campaigns & Intelligence Archive

🔔 Subscribe to Alerts
No recent breaking campaign alerts recorded in the FlagThis threat database.
Copied to clipboard

LINK COPIED TO CLIPBOARD