Threat actors targeting Financial Services
Part of Threatwake, a free morning threat-intelligence dashboard.
58 threat actor groups tracked in MITRE ATT&CK are documented as targeting financial services, between them using 362 distinct ATT&CK techniques. 8 financial services victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against financial services
- T1059.001 · PowerShell (execution) — used by 36 of 58 financial services actors (62%)
- T1588.002 · Tool (resource-development) — used by 34 of 58 financial services actors (59%)
- T1204.002 · Malicious File (execution) — used by 33 of 58 financial services actors (57%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 31 of 58 financial services actors (53%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 30 of 58 financial services actors (52%)
- T1059.003 · Windows Command Shell (execution) — used by 28 of 58 financial services actors (48%)
- T1082 · System Information Discovery (discovery) — used by 25 of 58 financial services actors (43%)
- T1053.005 · Scheduled Task (execution) — used by 23 of 58 financial services actors (40%)
- T1036.005 · Match Legitimate Resource Name or Location (stealth) — used by 21 of 58 financial services actors (36%)
- T1047 · Windows Management Instrumentation (execution) — used by 20 of 58 financial services actors (34%)
- T1566.002 · Spearphishing Link (initial-access) — used by 20 of 58 financial services actors (34%)
- T1059.005 · Visual Basic (execution) — used by 19 of 58 financial services actors (33%)
Threat actor groups
- Lazarus Group (also: Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC) — 93 documented techniques
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- OilRig (also: COBALT GYPSY, IRN2, APT34, Helix Kitten) — 76 documented techniques
- MuddyWater (also: Earth Vetala, MERCURY, Static Kitten, Seedworm) — 68 documented techniques
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- Scattered Spider (also: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944) — 64 documented techniques
- Wizard Spider (also: UNC1878, TEMP.MixMaster, Grim Spider, FIN12) — 64 documented techniques
- APT38 (also: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima) — 56 documented techniques
- TeamTNT — 56 documented techniques
- Contagious Interview (also: DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER) — 54 documented techniques
- FIN13 (also: Elephant Beetle) — 53 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- Earth Lusca (also: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX) — 44 documented techniques
- MirrorFace (also: Earth Kasha) — 43 documented techniques
- Storm-0501 — 42 documented techniques
- RedCurl — 41 documented techniques
- FIN6 (also: Magecart Group 6, ITG08, Skeleton Spider, TAAL) — 40 documented techniques
- APT-C-36 (also: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98) — 38 documented techniques
- FIN8 (also: Syssphinx) — 36 documented techniques
- Rocke — 36 documented techniques
- Aquatic Panda — 35 documented techniques
- Cobalt Group (also: GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider) — 34 documented techniques
- TA505 (also: Hive0065, Spandex Tempest, CHIMBORAZO) — 34 documented techniques
- Indrik Spider (also: Evil Corp, Manatee Tempest, DEV-0243, UNC2165) — 33 documented techniques
- APT42 — 32 documented techniques
- GALLIUM (also: Granite Typhoon) — 31 documented techniques
- Storm-1811 — 31 documented techniques
- Moonstone Sleet (also: Storm-1789) — 30 documented techniques
- Silence (also: Whisper Spider) — 28 documented techniques
- WIRTE (also: Ashen Lepus) — 26 documented techniques
- Blue Mockingbird — 22 documented techniques
- APT19 (also: Codoso, C0d0so0, Codoso Team, Sunshop Group) — 21 documented techniques
- Cinnamon Tempest (also: DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT) — 19 documented techniques
- CURIUM (also: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc) — 19 documented techniques
- Molerats (also: Operation Molerats, Gaza Cybergang) — 16 documented techniques
- EXOTIC LILY — 15 documented techniques
- Tonto Team (also: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda) — 15 documented techniques
- BlackTech (also: Palmerworm) — 14 documented techniques
- TA551 (also: GOLD CABIN, Shathak) — 14 documented techniques
- admin@338 — 12 documented techniques
Ransomware groups currently hitting financial services
8 victims claimed in the current feed.
- CRPxO — 3 victims
- Global Secret Group — 3 victims
- coinbasecartel — 1 victim
- anubis — 1 victim
Latest financial services security news
- Contributing to U.K. financial sector resilience as a critical third party
- AWS designated as a critical third party to the UK financial sector
Threat intelligence by sector
- Healthcare
- Government & Defense
- Technology
- Manufacturing
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.