Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0102
MITRE ATT&CK Group

Wizard Spider (G0102)

UNC1878TEMP.MixMasterGrim SpiderFIN12GOLD BLACKBURNITG23Periwinkle TempestDEV-0193Pistachio TempestDEV-0237
ShareXLinkedInRedditHN

[Wizard Spider](https://attack.mitre.org/groups/G0102) is a Russia-based financially motivated threat group originally known for the creation and deployment of [TrickBot](https://attack.mitre.org/software/S0266) since at least 2016. [Wizard Spider](https://attack.mitre.org/groups/G0102) possesses a diverse arsenal of tools and has conducted ransomware campaigns against a variety of organizations, ranging from major corporations to hospitals.(Citation: CrowdStrike Ryuk January 2019)(Citation: DHS/CISA Ransomware Targeting Healthcare October 2020)(Citation: CrowdStrike Wizard Spider October 2020)

▪Techniques used (64)

T1136.001Local AccountT1588.003Code Signing CertificatesT1210Exploitation of Remote ServicesT1560.001Archive via UtilityT1059.003Windows Command ShellT1047Windows Management InstrumentationT1588.002ToolT1543.003Windows ServiceT1021.002SMB/Windows Admin SharesT1074Data StagedT1078.002Domain AccountsT1055Process InjectionT1021Remote ServicesT1021.001Remote Desktop ProtocolT1550.002Pass the HashT1222.001Windows PermissionsT1570Lateral Tool TransferT1204.002Malicious FileT1053.005Scheduled TaskT1027.010Command ObfuscationT1070.004File DeletionT1552.006Group Policy PreferencesT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1685Disable or Modify ToolsT1518.001Security Software DiscoveryT1218.011Rundll32T1558.003KerberoastingT1059.001PowerShellT1567.002Exfiltration to Cloud StorageT1112Modify RegistryT1490Inhibit System RecoveryT1133External Remote ServicesT1547.004Winlogon Helper DLLT1036.004Masquerade Task or ServiceT1087.002Domain AccountT1518.002Backup Software DiscoveryT1071.001Web ProtocolsT1553.002Code SigningT1136.002Domain AccountT1074.001Local Data StagingT1557.001Name Resolution Poisoning and SMB RelayT1105Ingress Tool TransferT1003.003NTDST1016System Network Configuration DiscoveryT1585.002Email AccountsT1033System Owner/User DiscoveryT1078Valid AccountsT1204.001Malicious LinkT1003.001LSASS MemoryT1041Exfiltration Over C2 ChannelT1566.001Spearphishing AttachmentT1003.002Security Account ManagerT1489Service StopT1566.002Spearphishing LinkT1018Remote System DiscoveryT1005Data from Local SystemT1082System Information DiscoveryT1555.004Windows Credential ManagerT1135Network Share DiscoveryT1569.002Service ExecutionT1547.001Registry Run Keys / Startup FolderT1021.006Windows Remote ManagementT1055.001Dynamic-link Library InjectionT1197BITS Jobs

▪Software used (22)

S0266TrickBotmalwareS0552AdFindtoolS0190BITSAdmintoolS9001SystemBCmalwareS0521BloodHoundtoolS0097PingtoolS0534BazarmalwareS0349LaZagnetoolS0359NltesttoolS0632GrimAgentmalwareS0024DyremalwareS0446RyukmalwareS0575ContimalwareS0367EmotetmalwareS1071RubeustoolS0002MimikatztoolS0504AnchormalwareS0659DiavolmalwareS0039NettoolS0363EmpiretoolS0029PsExectoolS0154Cobalt Strikemalware
G0102on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.