HC3 Threat Briefing TLP White: TrickBot, Ryuk, and the HPH Sector

November 12, 2020

Who is WIZARD SPIDER?

TrickBot is run by cybercriminal group “WIZARD SPIDER” (named by CrowdStrike), UNC1878, or “Team9”

  • Alleged to be affiliated with Russian cybercrime rings
  • Affiliated with GRIM SPIDER, LUNAR SPIDER, and MUMMY SPIDER
  • Some members were part of the group that operated the banking Trojan malware Dyre (Dyreza)
  • Dyreza ceased operating in November 2015 after Russian law enforcement raided the entertainment company believed to be behind it
  • Toolset covers the entire attack chain and frequently uses the combination of Emotet > TrickBot > Ryuk

Read the entire report under Key Resources.

Related Resources

Testimony
Public
John Riggi, AHA senior advisor for cybersecurity and risk, testimony before the Senate Homeland Security and Governmental Affairs Committee on defending…
Special Bulletin
Member
Federal agencies this morning are providing new information on an imminent ransomware threat to U.S. hospitals.
Special Bulletin
Member
The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS)…
Issue Landing Page
The number of large-scale data breaches at American health care organization increased 65% from 2010 to 2016. As a result, federal agencies are increasing…
Guides/Reports
Trusted insiders, both witting and unwitting, can cause grave harm to your organizations facilities, resources, information, and personnel. Insider incidents…
Standards/Guidelines
Public
Agent Tesla is an established Remote Access Trojan (RAT) written in .Net. A successful deployment of Agent Tesla provides attackers with full computer or…