← Back to all threat actors

Indrik Spider

Also known as Evil Corp, Manatee Tempest, DEV-0243, UNC2165
Tracked as G0119

Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransomware operations using BitPaymer, WastedLocker, and Hades ransomware. Following U.S. sanctions and an indictment in 2019, Indrik Spider changed their tactics and diversified their toolset.

How we source and review actor profiles
Motivation
ransomware
Sectors
financial-services
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityAlias: Evil Corp

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Manatee Tempest

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: DEV-0243

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC2165

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G0119

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Indrik SpiderCanonical Name
DEV-0243Alias
Evil CorpAlias
Manatee TempestAlias
UNC2165Alias
G0119Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...