Threat actors targeting Education
Part of Threatwake, a free morning threat-intelligence dashboard.
30 threat actor groups tracked in MITRE ATT&CK are documented as targeting education, between them using 339 distinct ATT&CK techniques. 4 education victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against education
- T1588.002 · Tool (resource-development) — used by 22 of 30 education actors (73%)
- T1059.001 · PowerShell (execution) — used by 20 of 30 education actors (67%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 19 of 30 education actors (63%)
- T1204.002 · Malicious File (execution) — used by 17 of 30 education actors (57%)
- T1071.001 · Web Protocols (command-and-control) — used by 13 of 30 education actors (43%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 13 of 30 education actors (43%)
- T1005 · Data from Local System (collection) — used by 12 of 30 education actors (40%)
- T1036.005 · Match Legitimate Resource Name or Location (stealth) — used by 12 of 30 education actors (40%)
- T1190 · Exploit Public-Facing Application (initial-access) — used by 12 of 30 education actors (40%)
- T1560.001 · Archive via Utility (collection) — used by 12 of 30 education actors (40%)
- T1583.001 · Domains (resource-development) — used by 12 of 30 education actors (40%)
- T1016 · System Network Configuration Discovery (discovery) — used by 11 of 30 education actors (37%)
Threat actor groups
- Kimsuky (also: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) — 130 documented techniques
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- Magic Hound (also: TA453, COBALT ILLUSION, Charming Kitten, ITG18) — 78 documented techniques
- Turla (also: IRON HUNTER, Group 88, Waterbug, WhiteBear) — 68 documented techniques
- APT29 (also: IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) — 66 documented techniques
- VOID MANTICORE (also: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma) — 63 documented techniques
- APT39 (also: ITG07, Chafer, Remix Kitten) — 53 documented techniques
- Leviathan (also: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK) — 50 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- Earth Lusca (also: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX) — 44 documented techniques
- HAFNIUM (also: Operation Exchange Marauder, Silk Typhoon) — 44 documented techniques
- LAPSUS$ (also: DEV-0537, Strawberry Tempest) — 43 documented techniques
- MirrorFace (also: Earth Kasha) — 43 documented techniques
- HEXANE (also: Lyceum, Siamesekitten, Spirlin) — 36 documented techniques
- Aquatic Panda — 35 documented techniques
- TA505 (also: Hive0065, Spandex Tempest, CHIMBORAZO) — 34 documented techniques
- APT42 — 32 documented techniques
- INC Ransom (also: GOLD IONIC) — 25 documented techniques
- APT19 (also: Codoso, C0d0so0, Codoso Team, Sunshop Group) — 21 documented techniques
- Star Blizzard (also: SEABORGIUM, Callisto Group, TA446, COLDRIVER) — 20 documented techniques
- Daggerfly (also: Evasive Panda, BRONZE HIGHLAND) — 17 documented techniques
- Molerats (also: Operation Molerats, Gaza Cybergang) — 16 documented techniques
- Tonto Team (also: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda) — 15 documented techniques
- Silent Librarian (also: TA407, COBALT DICKENS) — 13 documented techniques
- Aoqin Dragon — 9 documented techniques
- Metador — 9 documented techniques
- DarkHydrus — 7 documented techniques
- Winnti Group (also: Blackfly) — 6 documented techniques
- SilverTerrier — 4 documented techniques
- APT-C-23 (also: Mantis, Arid Viper, Desert Falcon, TAG-63) — 0 documented techniques
Ransomware groups currently hitting education
4 victims claimed in the current feed.
- safepay — 2 victims
- chaos — 1 victim
- qilin — 1 victim
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Manufacturing
- Energy & Utilities
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.