Evil Corp, also tracked as Indrik Spider, Gold Drake, DEV-0243, Manatee Tempest, and UNC2165, is a long-running Russian cybercrime group best known for operating the Dridex malware ecosystem and later conducting targeted ransomware intrusions. The group has been active since at least the mid-2010s and has been publicly linked to financially motivated operations involving banking trojans, large-scale malspam, malware loaders, and enterprise ransomware. U.S. sanctions imposed in 2019 against Evil Corp members are widely associated with the group’s subsequent rebranding and tooling changes. Evil Corp built much of its reputation through Dridex, a modular banking trojan and malware delivery platform used to steal banking credentials, capture screenshots, perform keylogging and browser-injection activity, and deliver additional payloads. Dridex campaigns relied heavily on phishing emails, malicious attachments, macro-enabled documents, compressed archives, and social engineering. The group also used fake software-update lures and compromised legitimate websites to deliver malware through the SocGholish framework, which has been observed distributing Dridex, NetSupport RAT, WastedLocker, and Hades. Over time, Evil Corp shifted from broad banking-malware activity toward targeted post-compromise ransomware operations. Dridex infections were used to gain footholds that later enabled deployment of BitPaymer, and the group has also been linked with WastedLocker, Hades, and Entropy-related activity. WastedLocker is strongly associated with Evil Corp and was used in targeted attacks against large enterprises, particularly in North America. Hades has been assessed as a later variant derived from WastedLocker and used in part to evade sanctions-related scrutiny. Reporting has also linked Evil Corp to Locky campaigns and to broader malware spam operations, though some historical reporting overlaps with TA505 and should be treated carefully where attribution is not exclusive. Operationally, Evil Corp combines initial access, malware staging, persistence, reconnaissance, credential theft, lateral movement, and hands-on-keyboard post-exploitation. Observed tradecraft includes PowerShell execution, use of batch scripts, downloading additional tools and malware onto compromised hosts, abuse of compromised servers and websites for staging or fake-update delivery, credential harvesting from files, and use of Cobalt Strike and legitimate administrative utilities for internal movement and ransomware deployment. In ransomware intrusions, the group has been observed prioritizing high-value enterprise systems, including file servers, databases, virtualized infrastructure, and systems tied to business operations. The group’s dominant motivation is financial gain. Its activity spans banking fraud enablement, credential theft, malware delivery, and high-value ransomware monetization. Evil Corp remains one of the most prominent Russian cybercriminal actors associated with the evolution from banking trojans to targeted enterprise ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
27 malware families attributed to this actor across reporting.
22 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Les vecteurs d’attaque changent rapidement. Ainsi, le passage de la version 3 à la version 4 de Dridex début 2017 a été accompagné de l’ajout de la faille 0-day MS Word (CVE-2017-0199)... Faille permettant de dissimuler des instructions malveillantes dans un document sauvegardé au format .RTF.
the attackers initially accessed targeted organizations’ networks with ProxyShell, an exploit of vulnerabilities in Microsoft Exchange
The vulnerability, identified as CVE-2024-37085, involves a domain group whose members are granted full administrative access to the ESXi hypervisor by default without proper validation... VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named “ESX Admins” to have full administrative access by default.
GTIG identified UNC2165... leveraging CVE-2025-8088 to distribute malware in mid-July 2025.
Beukema added that "there is a reason attackers still like LNK files - users quickly click through these sorts of warnings. Otherwise, CVE-2025-9491 wouldn't have been as 'successful' as it was either." CVE-2025-9491 ... can be exploited to hide command-line arguments by using excessive whitespace padding. ... widely exploited by at least 11 state-sponsored groups and cybercrime gangs ... Mustang Panda ... exploiting this Windows vulnerability in zero-day attacks ... to deploy the PlugX remote access trojan (RAT).
249 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Financially motivated actor mentioned in unrelated profile entries.
Mentioned only as a background association tied to an infrastructure operator, not as a focus of the article.
Cybercriminal group cited as using the sanctioned bulletproof hosting service Media Land LLC.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.