Skip to main content
Mallory
3 malware families

WizardSpider

Also known asWizardSpider

Wizard Spider is a criminal threat actor associated in the provided content with use of Conti ransomware. The content links the group to the 2021 ransomware attack on Ireland's Health Service Executive (HSE), which caused months of disruption and millions in damage. According to the cited PWC report, the intrusion began on 16 March 2021 when a user opened a malicious Microsoft Excel attachment delivered via phishing email. PWC attributed the intrusion to Wizard Spider, stated the attackers likely exploited an unpatched known vulnerability to gain access to HSE's Active Directory domain, and reported that the group maintained access for roughly two months before deploying the final Conti v3 payload on 14 May 2021. The content also states that HSE personnel had observed Wizard Spider activity before detonation and that antivirus detections included Cobalt Strike and Mimikatz. During the intrusion, the group reportedly compromised systems in multiple hospitals. The content further describes leaked internal chats from the Russia-affiliated Conti ransomware gang and notes that Wizard Spider used Conti ransomware in the HSE attack. Separately, Sophos reported a case involving a Canadian healthcare organization where Conti and the Karma ransomware gang both gained access via the ProxyShell exploit; in that incident, Conti encrypted much of the organization's data and dropped a batch script to disable Windows Defender before deploying its ransomware payload. Alias directly provided in the content: wizardspider.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Health Care Equipment & Services
  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇮🇪 Ireland
MITRE ATT&CK

Tradecraft

8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics10 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.003
Windows Command Shell
T1204
User Execution
T1204.002
Malicious File
TA0004
Privilege Escalation
1 technique
T1068
Exploitation for Privilege Escalation
TA0006
Credential Access
1 technique
T1003
OS Credential Dumping
TA0007
Discovery
1 technique
T1482
Domain Trust Discovery
TA0040
Impact
1 technique
T1486×2
Data Encrypted for Impact
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping8

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.