MITRE ATT&CK G0102
Aliases: Trickbot Group, Conti, UNC1878, Grim Spider
Official Attribution Source: U.S. Department of Justice Indictment (N.D. Ohio)

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
2
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G0102 (Wizard Spider).
  • Linked to 1 primary court prosecution records.
  • Identified 2 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to Wizard Spider Technique frequencies extracted from verified indictments for Wizard Spider. T1566.001 Spearphishing Attachment 1 incidents T1003 OS Credential Dumping 1 incidents T1486 Data Encrypted for Impact 1 incidents
Technique frequencies extracted from verified indictments for Wizard Spider.
ATT&CK Techniques Mapped to Wizard Spider
Technique Frequency
T1566.001 Spearphishing Attachment 1 incidents
T1003 OS Credential Dumping 1 incidents
T1486 Data Encrypted for Impact 1 incidents

Prosecution Cases Attributed to This Actor

sentenced 2021-02-18

U.S. v. Alla Witte & Vladimir Dunaev (Trickbot Malware Group)

Key software developers and coders of the transnational Trickbot cybercrime group charged with infecting millions of victim computers with banking trojans and facilitating Conti/Ryuk ransomware deployments against hospitals.

3 techniques View case →
OPERATIONAL DEFENSE

Targeted Defensive Hardening for Wizard Spider

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.