Wizard Spider, Gold Blackburn

Description

Wizard Spider is reportedly associated with Lunar Spider.

(Crowdstrike) The Wizard Spider threat group is the Russia-based operator of the TrickBot banking malware. This group represents a growing criminal enterprise of which Grim Spider appears to be a subset. The Lunar Spider threat group is the Eastern European-based operator and developer of the commodity banking malware called BokBot (aka IcedID), which was first observed in April 2017. The BokBot malware provides Lunar Spider affiliates with a variety of capabilities to enable credential theft and wire fraud, through the use of webinjects and a malware distribution function.

Dyre has been observed to be distributed by Cutwail (operated by Narwhal Spider), as well as their own botnets Gophe and Upatre.

TrickBot has been observed to be distributed via Emotet (operated by Mummy Spider, TA542), BokBot (operated by Lunar Spider), Smoke Loader (operated by Smoky Spider), DanaBot (operated by Scully Spider, TA547), Kelihos (operated by Zombie Spider), Necurs (operated by Monty Spider) and Taurus Loader (operated by Venom Spider, Golden Chickens), as well as their own botnet Gophe.

Names

NameName-Giver
Wizard SpiderCrowdStrike
Grim SpiderCrowdStrike
TEMP.MixMasterFireEye
Gold BlackburnSecureWorks
Gold UlrickSecureWorks
ITG23IBM
DEV-0193Microsoft
Storm-0230Microsoft
Periwinkle TempestMicrosoft

Country

Motivation

  • Financial crime
  • Financial gain

First Seen

2014

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

480940e0-47b0-4295-9067-c2500ccfdaec

Last Card Change

2025-06-28