Threat actors targeting Energy & Utilities
Part of Threatwake, a free morning threat-intelligence dashboard.
24 threat actor groups tracked in MITRE ATT&CK are documented as targeting energy & utilities, between them using 323 distinct ATT&CK techniques. 5 energy & utilities victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against energy & utilities
- T1059.001 · PowerShell (execution) — used by 18 of 24 energy & utilities actors (75%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 18 of 24 energy & utilities actors (75%)
- T1588.002 · Tool (resource-development) — used by 17 of 24 energy & utilities actors (71%)
- T1204.002 · Malicious File (execution) — used by 15 of 24 energy & utilities actors (63%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 15 of 24 energy & utilities actors (63%)
- T1053.005 · Scheduled Task (execution) — used by 13 of 24 energy & utilities actors (54%)
- T1583.001 · Domains (resource-development) — used by 13 of 24 energy & utilities actors (54%)
- T1005 · Data from Local System (collection) — used by 11 of 24 energy & utilities actors (46%)
- T1016 · System Network Configuration Discovery (discovery) — used by 11 of 24 energy & utilities actors (46%)
- T1027.013 · Encrypted/Encoded File (stealth) — used by 11 of 24 energy & utilities actors (46%)
- T1036.005 · Match Legitimate Resource Name or Location (stealth) — used by 11 of 24 energy & utilities actors (46%)
- T1059.003 · Windows Command Shell (execution) — used by 11 of 24 energy & utilities actors (46%)
Threat actor groups
- Kimsuky (also: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) — 130 documented techniques
- APT28 (also: IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74) — 93 documented techniques
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- OilRig (also: COBALT GYPSY, IRN2, APT34, Helix Kitten) — 76 documented techniques
- MuddyWater (also: Earth Vetala, MERCURY, Static Kitten, Seedworm) — 68 documented techniques
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- Threat Group-3390 (also: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION) — 57 documented techniques
- UNC3886 — 49 documented techniques
- Ke3chang (also: APT15, Mirage, Vixen Panda, GREF) — 46 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- LAPSUS$ (also: DEV-0537, Strawberry Tempest) — 43 documented techniques
- Fox Kitten (also: UNC757, Parisite, Pioneer Kitten, RUBIDIUM) — 41 documented techniques
- APT-C-36 (also: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98) — 38 documented techniques
- HEXANE (also: Lyceum, Siamesekitten, Spirlin) — 36 documented techniques
- APT42 — 32 documented techniques
- APT33 (also: HOLMIUM, Elfin, Peach Sandstorm) — 31 documented techniques
- APT19 (also: Codoso, C0d0so0, Codoso Team, Sunshop Group) — 21 documented techniques
- CURIUM (also: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc) — 19 documented techniques
- BITTER (also: T-APT-17) — 16 documented techniques
- Molerats (also: Operation Molerats, Gaza Cybergang) — 16 documented techniques
- Tonto Team (also: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda) — 15 documented techniques
- Moses Staff (also: DEV-0500, Marigold Sandstorm) — 12 documented techniques
- Winnti Group (also: Blackfly) — 6 documented techniques
- APT-C-23 (also: Mantis, Arid Viper, Desert Falcon, TAG-63) — 0 documented techniques
Ransomware groups currently hitting energy & utilities
5 victims claimed in the current feed.
- Global Secret Group — 3 victims
- Deadlock — 2 victims
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Manufacturing
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.