CSIDB logo
Threat actor

Wizard Spider

Attribution profile

Type
Crime Syndicate
Location
Russia
Known incidents
106 incidents
First seen
2019-04-26
Last seen
2023-05-05
Updated
2026-08-28 18:06
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Wizard Spider, also known as WIZARD SPIDER, ITA, Conti Ransomware, TrickBot, Conti Gang, ITG23, Conti-ryuk, Conti Group, Trickbot Group, Wizard Spider, Conti ransomware group, Conti, YTB-0006, Conti ransomware gang, Trickbot, Conti Team, is a Russian‑linked cybercrime operation that functions as a ransomware‑as‑a‑service platform. The group is publicly associated with the Wizard Spider cybercrime collective and has been observed deploying the Conti ransomware strain alongside related malware families such as TrickBot, BazarLoader and Ryuk. While the exact geographic base is not disclosed in the source material, the actor is repeatedly described as Russia‑based in multiple reports.

The actor’s targeting spans a variety of sectors including healthcare, government, energy, aviation, manufacturing and retail, with observed victims in North America, Latin America and Europe. Strategic objectives evident from the material are primarily financial gain through ransom demands and double‑extortion tactics, whereby data is encrypted and threatened with public leak if payment is not made. Some incidents also demonstrate a disruptive aim, such as the shutdown of tax and customs platforms in Costa Rica that caused significant economic impact and the disruption of electricity administration systems that halted billing operations. The group’s public statements and leak site activity indicate a focus on monetizing access rather than pure espionage, although the theft of sensitive governmental and personal data is routinely reported.

Typical tactics involve initial access via phishing emails that deliver TrickBot or BazarLoader, followed by exploitation of vulnerabilities such as CVE‑2020‑0796 to escalate privileges. Once inside a network, the actors use tools like BloodHound to map Active Directory, Mimikatz to harvest credentials and RDP to move laterally, before deploying Conti ransomware to encrypt files. The group maintains a data leak site where stolen files are posted to pressure victims, and it has been observed issuing ransom demands ranging from several hundred thousand to tens of millions of dollars. Notable campaigns highlighted in the source material include the sustained attacks on Costa Rican government agencies in April 2022, the ransomware incident against Peru’s Dirección General de Inteligencia in May 2022, the compromise of Leon Medical Centers in Florida that exposed nearly two million patient‑related files, and the ransomware strike on the wind turbine manufacturer Nordex in April 2022. These examples illustrate the actor’s ability to affect critical infrastructure, healthcare providers and large enterprises across multiple regions.

Incidents

Attributed incidents are available to members.

106 incidents
CSIDB