Special Bulletin
HC3 Threat Briefing TLP White: TrickBot, Ryuk, and the HPH Sector
November 12, 2020
Who is WIZARD SPIDER?
TrickBot is run by cybercriminal group “WIZARD SPIDER” (named by CrowdStrike), UNC1878, or “Team9”
- Alleged to be affiliated with Russian cybercrime rings
- Affiliated with GRIM SPIDER, LUNAR SPIDER, and MUMMY SPIDER
- Some members were part of the group that operated the banking Trojan malware Dyre (Dyreza)
- Dyreza ceased operating in November 2015 after Russian law enforcement raided the entertainment company believed to be behind it
- Toolset covers the entire attack chain and frequently uses the combination of Emotet > TrickBot > Ryuk
Read the entire report under Key Resources.
Key Resources
Related Resources
Guides and Reports
Advisory
Hospitals That Are Oracle Customers Urged to Take Immediate Action to Address Security Vulnerability
Issue Landing Page
Issue Landing Page
Guides and Reports