Threat actors targeting Agriculture & Food
Part of Threatwake, a free morning threat-intelligence dashboard.
2 threat actor groups tracked in MITRE ATT&CK are documented as targeting agriculture & food, between them using 69 distinct ATT&CK techniques. 0 agriculture & food victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against agriculture & food
- T1078 · Valid Accounts (stealth) — used by 2 of 2 agriculture & food actors (100%)
- T1102.002 · Bidirectional Communication (command-and-control) — used by 2 of 2 agriculture & food actors (100%)
- T1567.002 · Exfiltration to Cloud Storage (exfiltration) — used by 2 of 2 agriculture & food actors (100%)
- T1583.006 · Web Services (resource-development) — used by 2 of 2 agriculture & food actors (100%)
- T1588.002 · Tool (resource-development) — used by 2 of 2 agriculture & food actors (100%)
- T1005 · Data from Local System (collection) — used by 1 of 2 agriculture & food actors (50%)
- T1008 · Fallback Channels (command-and-control) — used by 1 of 2 agriculture & food actors (50%)
- T1021.001 · Remote Desktop Protocol (lateral-movement) — used by 1 of 2 agriculture & food actors (50%)
- T1021.004 · SSH (lateral-movement) — used by 1 of 2 agriculture & food actors (50%)
- T1021.005 · VNC (lateral-movement) — used by 1 of 2 agriculture & food actors (50%)
- T1027.010 · Command Obfuscation (stealth) — used by 1 of 2 agriculture & food actors (50%)
- T1027.016 · Junk Code Insertion (stealth) — used by 1 of 2 agriculture & food actors (50%)
Threat actor groups
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- POLONIUM (also: Plaid Rain) — 7 documented techniques
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Manufacturing
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.