HC3 Threat Briefing TLP White: TrickBot, Ryuk, and the HPH Sector

November 12, 2020

Who is WIZARD SPIDER?

TrickBot is run by cybercriminal group “WIZARD SPIDER” (named by CrowdStrike), UNC1878, or “Team9”

  • Alleged to be affiliated with Russian cybercrime rings
  • Affiliated with GRIM SPIDER, LUNAR SPIDER, and MUMMY SPIDER
  • Some members were part of the group that operated the banking Trojan malware Dyre (Dyreza)
  • Dyreza ceased operating in November 2015 after Russian law enforcement raided the entertainment company believed to be behind it
  • Toolset covers the entire attack chain and frequently uses the combination of Emotet > TrickBot > Ryuk

Read the entire report under Key Resources.