WizardSpider_TLPWHITE_v.1.4.pdf
ID: 2b424ac0-7b02-48ef-abfc-12380160db96
STIX ID: report--2b424ac0-7b02-48ef-abfc-12380160db96
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2022-05-18
Last Modified Date: 2022-05-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This PRODAFT PTI report provides an in-depth technical analysis of the Wizard Spider criminal group (operators of Conti ransomware and related tooling), documenting their operational architecture (QBot/SystemBC, Cobalt Strike, intrusion and locker servers, cracking station, cold-calling system), exploitation of vulnerabilities (Log4j, CVE-2021-40444, ZeroLogon), detailed malware analysis (Linux ESXi and Windows Conti encryptors), extensive IOCs (hashes, IPs, domains), victim statistics (~128,036 SystemBC victims) and investigative evidence used for attribution and defensive guidance.
