logo

Evil_Corp__2024__Evil_Corp_-_Behind_the_Screens.pdf

ID: 019fe596-b7ca-4aa4-80eb-95a3c24d0e88

STIX ID: report--019fe596-b7ca-4aa4-80eb-95a3c24d0e88

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2024-10-01

Last Modified Date: 2024-10-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Evil Corp (Indrik Spider) is a long-running, Russia-based organised cybercrime group responsible for prolific banking malware and multiple ransomware families (Dridex, BitPaymer, DoppelPaymer, WastedLocker, Hades, PhoenixLocker, PayloadBIN, Macaw) that have extorted roughly $300M from victims across healthcare, government and critical infrastructure; the group is highly organised and sophisticated, has been linked to Russian intelligence activities, adapted tactics after 2019 sanctions and indictments, and remained active through 2024 including affiliations with other ransomware operators such as LockBit.