AHA Center for Health Innovation Market Scan
HC3 Threat Briefing TLP White: TrickBot, Ryuk, and the HPH Sector
November 12, 2020
Who is WIZARD SPIDER?
TrickBot is run by cybercriminal group “WIZARD SPIDER” (named by CrowdStrike), UNC1878, or “Team9”
- Alleged to be affiliated with Russian cybercrime rings
- Affiliated with GRIM SPIDER, LUNAR SPIDER, and MUMMY SPIDER
- Some members were part of the group that operated the banking Trojan malware Dyre (Dyreza)
- Dyreza ceased operating in November 2015 after Russian law enforcement raided the entertainment company believed to be behind it
- Toolset covers the entire attack chain and frequently uses the combination of Emotet > TrickBot > Ryuk
Read the entire report under Key Resources.
Key Resources
Related Resources
Special Bulletin
AHA Center for Health Innovation Market Scan