logo

WIZARD SPIDER: The Financial Empire Behind Global Ransomware Operations

ID: 986ffb84-824b-58cc-b58e-f4796c5dd23d

STIX ID: report--986ffb84-824b-58cc-b58e-f4796c5dd23d

Feed Name: Brandefense Blog

Threat Score
88/100

Date Published: 2026-01-14

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

WIZARD SPIDER is a highly organized, financially motivated criminal consortium (aka FIN12/Gold Blackburn/DEV-0193) active since at least 2016 that conducts large-scale ransomware and double-extortion campaigns worldwide. The report outlines their affiliate/RaaS model, TTPs—including phishing, loaders (TrickBot, BazarLoader), Cobalt Strike, and ransomware families (Ryuk, Conti, Black Basta)—recent campaign history through 2025 targeting healthcare, logistics, and manufacturing, observed impacts, and prioritized mitigations such as MFA, EDR/XDR, segmentation, and incident response preparedness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.