Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0119
MITRE ATT&CK Group

Indrik Spider (G0119)

Evil CorpManatee TempestDEV-0243UNC2165
ShareXLinkedInRedditHN

[Indrik Spider](https://attack.mitre.org/groups/G0119) is a Russia-based cybercriminal group that has been active since at least 2014. [Indrik Spider](https://attack.mitre.org/groups/G0119) initially started with the [Dridex](https://attack.mitre.org/software/S0384) banking Trojan, and then by 2017 they began running ransomware operations using [BitPaymer](https://attack.mitre.org/software/S0570), [WastedLocker](https://attack.mitre.org/software/S0612), and Hades ransomware. Following U.S. sanctions and an indictment in 2019, [Indrik Spider](https://attack.mitre.org/groups/G0119) changed their tactics and diversified their toolset.(Citation: Crowdstrike Indrik November 2018)(Citation: Crowdstrike EvilCorp March 2021)(Citation: Treasury EvilCorp Dec 2019)

▪Techniques used (33)

T1003.001LSASS MemoryT1587.001MalwareT1136Create AccountT1112Modify RegistryT1036.005Match Legitimate Resource Name or LocationT1007System Service DiscoveryT1583Acquire InfrastructureT1685Disable or Modify ToolsT1074.001Local Data StagingT1021.001Remote Desktop ProtocolT1555.005Password ManagersT1590Gather Victim Network InformationT1059.001PowerShellT1078.002Domain AccountsT1552.001Credentials In FilesT1567.002Exfiltration to Cloud StorageT1059.003Windows Command ShellT1484.001Group Policy ModificationT1047Windows Management InstrumentationT1078Valid AccountsT1486Data Encrypted for ImpactT1685.005Clear Windows Event LogsT1136.001Local AccountT1018Remote System DiscoveryT1059.007JavaScriptT1585.002Email AccountsT1105Ingress Tool TransferT1489Service StopT1012Query RegistryT1558.003KerberoastingT1204.002Malicious FileT1021.004SSHT1584.004Server

▪Software used (8)

S0695DonuttoolS0002MimikatztoolS0363EmpiretoolS0029PsExectoolS0384DridexmalwareS0612WastedLockermalwareS0570BitPaymermalwareS0154Cobalt Strikemalware
G0119on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.