APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
Evil Corp (aka Evil Corp, DEV-0243) · APT Atlas
Actors
/
Cybercrime
/
Europe
Evil Corp
G0119
CRIME
RU · Russia
AKA
DEV-0243 · TA505 (overlap) · Dridex Gang
CrowdStrike
:
INDRIK SPIDER
Mandiant
:
FIN11
Microsoft
:
Manatee Tempest
MITRE
:
G0119
Proofpoint
:
TA505
Secureworks
:
GOLD DRAKE
Russian-speaking cybercriminal syndicate behind Dridex banking malware and ransomware.
Targets
11
Sectors
17
Threat types
2
GIRs covered
0/480
Active since
2007
Pin to atlas
Watch
Share
Export
Also tracked as
6 vendor names · 3 other aliases
Open Rosetta Stone
CrowdStrike
INDRIK SPIDER
Mandiant
FIN11
Microsoft
Manatee Tempest
MITRE
G0119
Proofpoint
TA505
Secureworks
GOLD DRAKE
UNATTRIBUTED ALIASES
DEV-0243
TA505 (overlap)
Dridex Gang
Victimology
Geographic footprint · 11 countries
Region filter
Export
origin · Russia
targeted countries · 11
EUROPE ·
7
Austria
·
Switzerland
·
Germany
·
Spain
·
France
·
United Kingdom
·
Italy
OCEANIA ·
2
Australia
·
New Zealand
AMERICAS ·
2
Canada
·
United States
Sectors targeted
17 of 40
Government
100 actors
Aviation
22 actors
Financial Services
74 actors
Cryptocurrency
21 actors
Healthcare
47 actors
Telecom
72 actors
Retail & Hospitality
33 actors
NGOs & Dissidents
56 actors
Energy / Utilities
59 actors
Oil and Gas
21 actors
Education & Research
62 actors
Manufacturing (man)
50 actors
Media & Journalism
49 actors
Real Estate
10 actors
Hospitality
33 actors
Consulting / Professional Services
35 actors
Consumer Goods / Electronics
20 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
FIN · Financial Fraud
RAN · Ransomware
MITRE ATT&CK · 25 techniques
Reconnaissance
· 1
T1590
Gather Victim Network Information
Resource Development
· 1
T1583
Acquire Infrastructure
Execution
· 4
T1047
Windows Management Instrumentation
Persistence
· 1
T1136
Create Account
Credential Access
· 4
T1003.001
LSASS Memory
Discovery
· 3
T1007
System Service Discovery
T1012
Query Registry
Lateral Movement
· 2
T1021.001
Remote Desktop Protocol
T1021.004
SSH
Exfiltration
· 1
T1567.002
Exfiltration to Cloud Storage
Impact
· 2
T1486
Data Encrypted for Impact
Command And Control
· 1
T1105
Ingress Tool Transfer
Defense Impairment
· 2
T1112
Modify Registry
Stealth
· 3
T1036.005
Match Legitimate Resource Name or Location
T1078
Valid Accounts
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
25 techniques · layer format 4.5
Related actors
By origin and actor type
APT44
nation-state
Russia · 25 targets · since 2009
FIN10
cybercrime
unattributed · 1 targets · since 2013
FIN2
cybercrime
unattributed · 0 targets · since —
FIN6
cybercrime
Russia · 15 targets · since 2014
UNC1543
cybercrime
unattributed · 22 targets · since —
FIN3
cybercrime
unattributed · 1 targets · since —
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.007
JavaScript
T1552.001
Credentials In Files
T1555.005
Password Managers
T1558.003
Kerberoasting
T1018
Remote System Discovery
T1489
Service Stop
T1685
Disable or Modify Tools
T1078.002
Domain Accounts