Evil_Corp__2024__Evil_Corp_-_Behind_the_Screens.pdf
ID: 019fe596-b7ca-4aa4-80eb-95a3c24d0e88
STIX ID: report--019fe596-b7ca-4aa4-80eb-95a3c24d0e88
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2024-10-01
Last Modified Date: 2024-10-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Evil Corp (Indrik Spider) is a long-running, Russia-based organised cybercrime group responsible for prolific banking malware and multiple ransomware families (Dridex, BitPaymer, DoppelPaymer, WastedLocker, Hades, PhoenixLocker, PayloadBIN, Macaw) that have extorted roughly $300M from victims across healthcare, government and critical infrastructure; the group is highly organised and sophisticated, has been linked to Russian intelligence activities, adapted tactics after 2019 sanctions and indictments, and remained active through 2024 including affiliations with other ransomware operators such as LockBit.
