GRIM SPIDER is a sophisticated eCrime group known for targeting large organizations with Ryuk ransomware.
Analyst brief
GRIM SPIDER (also known as GOLD ULRICK) is a sophisticated eCrime group operating the Ryuk ransomware since August 2018, using 'big game hunting' tactics to target large organizations for high ransoms. The group is likely a cell within the Russia-based WIZARD SPIDER criminal enterprise, which is known for operating the TrickBot banking malware. The primary TTP involves deploying Ryuk ransomware, derived from Hermes source code, against enterprise environments following initial compromise, often via TrickBot. Defenders should prioritize detecting TrickBot infections as a precursor, monitoring for anomalous C2 traffic, and protecting against privilege escalation to domain admin to prevent widespread encryption.
GRIM SPIDER
GOLD ULRICK
unknown
GRIM SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER, a criminal enterprise of which GRIM SPIDER appears to be a cell. The WIZARD SPIDER threat group, known as the Russia-based operator of the TrickBot banking malware, had focused primarily on wire fraud in the past.
Similar to Samas and BitPaymer, Ryuk is specifically used to target enterprise environments. Code comparison between versions of Ryuk and Hermes ransomware indicates that Ryuk was derived from the Hermes source code and has been under steady development since its release. Hermes is commodity ransomware that has been observed for sale on forums and used by multiple threat actors. However, Ryuk is only used by GRIM SPIDER and, unlike Hermes, Ryuk has only been used to target enterprise environments. Since Ryuk’s appearance in August, the threat actors operating it have netted over 705.80 BTC across 52 transactions for a total current value of $3,701,893.98 USD.
Grim Spider is reportedly associated with Lunar Spider and Wizard Spider.
What malware does GRIM SPIDER use as the initial access vector before deploying Ryuk ransomware?+
GRIM SPIDER often uses TrickBot malware as the initial access vector, as the group is a cell within the WIZARD SPIDER criminal enterprise which operates the TrickBot banking malware.
From which malware's source code is the Ryuk ransomware used by GRIM SPIDER derived?+
The Ryuk ransomware is derived from the source code of the Hermes ransomware.