Skip to content
Threat Intelligence Tarot
Vol. II · 97
Russia (FSB-linked, Maksim Yakubets)
G0119
risk 5/5
The Sanctioned Serpent
Evil Corp
Indrik Spider · UNC2165 · Gold Drake
Financial institutionsInsuranceHealthcareManufacturingPrivate sector globally
Active since ~2007 · Financial crime, Ransomware, Banking fraud
The Sanctioned Serpent sheds its skin to evade the law, emerging as a new criminal enterprise the moment the last one is named. Sanctioned but not stopped, it proves that financial penalties alone cannot tame the beast.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
T1566.001
Spearphishing Attachment
Initial Access
T1059.003
Windows Command Shell
Execution
T1486
Data Encrypted for Impact
Impact
T1021.001
Remote Desktop Protocol
Lateral Movement
T1078
Valid Accounts
Defense Evasion
T1074
Data Staged
Collection
T1490
Inhibit System Recovery
Impact
Notable Operations
  • Dridex banking trojan causing $100M+ in losses globally
  • WastedLocker ransomware targeting US corporations
  • US Treasury OFAC sanctions (2019) - first ransomware group sanctioned
  • Continuous rebranding (BitPaymer, Hades, Phoenix) to evade sanctions
Defenses
  • Email gateway blocking macro-enabled Office documents from external senders
    CIS Control 9
  • Endpoint detection with behavioral analytics to catch Dridex-style banking trojan activity
    CIS Control 10
  • Offline immutable backups tested quarterly for ransomware recovery
    CIS Control 11
  • OFAC sanctions screening before any ransom payment consideration
    Regulatory compliance
Reversed: Their Weakness
US Treasury sanctions force its affiliates to avoid ransom payment to maintain banking access. Victim organizations that refuse to pay sanctioned entities remove the economic incentive entirely.

Share this adversary profile

Compare →

swipe to browse

Data sourced from MITRE ATT&CK. For educational purposes.