Evil Corp, also known as INDRIK SPIDER, Gold Drake, DEV-0243, and Manatee Tempest, is a Russia-based cybercriminal group active since at least 2007. Its dominant motivation is financial gain through banking fraud and targeted ransomware attacks. The financially motivated activity cluster UNC2165 has significant operational overlaps with Evil Corp. The group has links to the Russian state, but its established operations are primarily financially motivated rather than a uniformly state-directed espionage campaign. Evil Corp is closely associated with the development and distribution of Dridex, a modular banking trojan that evolved into a malware downloader. Dridex campaigns use phishing messages, malicious attachments, and document macros to compromise victims, steal online-banking credentials through browser manipulation and keylogging, and transmit captured information. Financial institutions and their customers are established targets, including institutions in the United States. The group subsequently adopted targeted, high-return ransomware operations commonly described as big-game hunting, using BitPaymer to encrypt domain-controlled systems. Its ransomware operations have also used WastedLocker, Hades, and Phoenix. UNC2165 has conducted multiple attacks using LockBit ransomware. Documented post-compromise techniques include Active Directory enumeration with PowerView, credential dumping with ProcDump through Cobalt Strike, and execution of batch scripts on compromised systems. Manatee Tempest has exploited CVE-2024-37085 to obtain administrative access to domain-joined VMware ESXi hypervisors through abuse of Active Directory group membership. Evil Corp has also been linked to SocGholish-based malware delivery. Following U.S. Treasury sanctions in December 2019, the group changed operational branding and ransomware variants to obscure its identity and circumvent restrictions affecting ransom payments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named “ESX Admins” to have full administrative access by default.
ZDI identified nearly 1,000 malicious .lnk files abusing ZDI-CAN-25373 (aka ZDI-25-148), a vulnerability that allows attackers to execute hidden malicious commands on a victim’s machine by leveraging crafted shortcut files.
Les vecteurs d’attaque changent rapidement. Ainsi, le passage de la version 3 à la version 4 de Dridex début 2017 a été accompagné de l’ajout de la faille 0-day MS Word (CVE-2017-0199)... Faille permettant de dissimuler des instructions malveillantes dans un document sauvegardé au format .RTF.
the attackers initially accessed targeted organizations’ networks with ProxyShell, an exploit of vulnerabilities in Microsoft Exchange
GTIG identified UNC2165... leveraging CVE-2025-8088 to distribute malware in mid-July 2025.
252 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Indrik Spider is listed in the Annotations section of the Windows AD Computer SPN Modified By User Account detection.
Mentioned as an example of a criminal self-brand that may be known to targeted organizations.
Listed only in technique annotations. The content does not attribute ResetNightmare exploitation or a specific campaign to this group.
Indrik Spider is listed in the detection's annotations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.