PIZZO SPIDER — Ransomware Profile

PIZZO SPIDER is CrowdStrike's cryptonym for DD4BC ("DDoS for Bitcoin"), a financially motivated extortion crew that, according to CrowdStrike, was sending ransom emails as early as April 2014 threatening to knock victims offline with DDoS unless they paid in Bitcoin. Akamai's PLXsert team tracked 141 DD4BC attacks between September 2014 and August 2015, first against online gambling operators and later against financial services, media and retail, with the group escalating to threats of public exposure on social media. Europol described DD4BC as a "cybercriminal group" responsible for "several Bitcoin extortion campaigns since mid-2014", and in Operation Pleiades on 15-16 December 2015 arrested a main target and detained a second suspect in Bosnia and Herzegovina, where the UK Metropolitan Police Cyber Crime Unit had identified key members of the network. The group extorted through denial of service rather than file encryption and is associated with no ransomware family, so it is classified here under financially motivated extortion crime; no vendor or law-enforcement source describes it as ideologically motivated.

Also tracked as

DD4BC, Ambiorx, DDoS for Bitcoin, DDoS 4 Bitcoin

Vendor research

Read the full analysis on IntelFusions