VICE SPIDER is a Russian-speaking ransomware group known for identity-based attacks centered on Kerberoasting and credential theft.
Analyst brief
VICE SPIDER is a Russian-speaking ransomware group active since at least April 2021, known for a sharp rise in identity-based attacks, particularly a 583% increase in Kerberoasting incidents. They primarily exploit weaknesses in the Kerberos authentication protocol to crack user passwords, with a focus on credential theft and lateral movement. Defenders should prioritize monitoring for suspicious Kerberos service ticket requests, enforcing strong password policies, and detecting anomalous authentication attempts across the network.
VICE SPIDER
unknown
Vice Spider is a Russian-speaking ransomware group that has been active since at least April 2021 and is linked to a significant increase in identity-based attacks, with a reported 583% rise in Kerberoasting incidents. CrowdStrike attributes 27% of these intrusions specifically to Vice Spider, which exploits vulnerabilities in the Kerberos authentication protocol to crack user passwords.
What is the primary attack technique used by VICE SPIDER?+
VICE SPIDER primarily focuses on the Kerberoasting technique, exploiting vulnerabilities in the Kerberos authentication protocol to crack user passwords.