Threat actors targeting Government & Defense
Part of Threatwake, a free morning threat-intelligence dashboard.
105 threat actor groups tracked in MITRE ATT&CK are documented as targeting government & defense, between them using 437 distinct ATT&CK techniques. 1 government & defense victim appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against government & defense
- T1204.002 · Malicious File (execution) — used by 62 of 105 government & defense actors (59%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 60 of 105 government & defense actors (57%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 60 of 105 government & defense actors (57%)
- T1059.001 · PowerShell (execution) — used by 59 of 105 government & defense actors (56%)
- T1588.002 · Tool (resource-development) — used by 54 of 105 government & defense actors (51%)
- T1059.003 · Windows Command Shell (execution) — used by 45 of 105 government & defense actors (43%)
- T1053.005 · Scheduled Task (execution) — used by 41 of 105 government & defense actors (39%)
- T1036.005 · Match Legitimate Resource Name or Location (stealth) — used by 40 of 105 government & defense actors (38%)
- T1082 · System Information Discovery (discovery) — used by 40 of 105 government & defense actors (38%)
- T1083 · File and Directory Discovery (discovery) — used by 39 of 105 government & defense actors (37%)
- T1005 · Data from Local System (collection) — used by 38 of 105 government & defense actors (36%)
- T1071.001 · Web Protocols (command-and-control) — used by 38 of 105 government & defense actors (36%)
Threat actor groups
- Kimsuky (also: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) — 130 documented techniques
- APT28 (also: IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74) — 93 documented techniques
- Lazarus Group (also: Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC) — 93 documented techniques
- Mustang Panda (also: TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS) — 85 documented techniques
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- Sandworm Team (also: ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group)) — 79 documented techniques
- APT32 (also: SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone) — 78 documented techniques
- Magic Hound (also: TA453, COBALT ILLUSION, Charming Kitten, ITG18) — 78 documented techniques
- OilRig (also: COBALT GYPSY, IRN2, APT34, Helix Kitten) — 76 documented techniques
- Gamaredon Group (also: IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon) — 70 documented techniques
- MuddyWater (also: Earth Vetala, MERCURY, Static Kitten, Seedworm) — 68 documented techniques
- Turla (also: IRON HUNTER, Group 88, Waterbug, WhiteBear) — 68 documented techniques
- APT29 (also: IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) — 66 documented techniques
- Wizard Spider (also: UNC1878, TEMP.MixMaster, Grim Spider, FIN12) — 64 documented techniques
- VOID MANTICORE (also: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma) — 63 documented techniques
- Threat Group-3390 (also: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION) — 57 documented techniques
- APT38 (also: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima) — 56 documented techniques
- Dragonfly (also: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192) — 56 documented techniques
- APT39 (also: ITG07, Chafer, Remix Kitten) — 53 documented techniques
- Leviathan (also: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK) — 50 documented techniques
- UNC3886 — 49 documented techniques
- Ember Bear (also: UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard) — 47 documented techniques
- Ke3chang (also: APT15, Mirage, Vixen Panda, GREF) — 46 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- APT3 (also: Gothic Panda, Pirpi, UPS Team, Buckeye) — 44 documented techniques
- Earth Lusca (also: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX) — 44 documented techniques
- HAFNIUM (also: Operation Exchange Marauder, Silk Typhoon) — 44 documented techniques
- LAPSUS$ (also: DEV-0537, Strawberry Tempest) — 43 documented techniques
- MirrorFace (also: Earth Kasha) — 43 documented techniques
- Fox Kitten (also: UNC757, Parisite, Pioneer Kitten, RUBIDIUM) — 41 documented techniques
- Patchwork (also: Hangover Group, Dropping Elephant, Chinastrats, MONSOON) — 41 documented techniques
- BRONZE BUTLER (also: REDBALDKNIGHT, Tick) — 40 documented techniques
- Tropic Trooper (also: Pirate Panda, KeyBoy) — 40 documented techniques
- APT-C-36 (also: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98) — 38 documented techniques
- HEXANE (also: Lyceum, Siamesekitten, Spirlin) — 36 documented techniques
- Aquatic Panda — 35 documented techniques
- APT42 — 32 documented techniques
- GALLIUM (also: Granite Typhoon) — 31 documented techniques
- Moonstone Sleet (also: Storm-1789) — 30 documented techniques
- Sidewinder (also: T-APT-04, Rattlesnake) — 30 documented techniques
Ransomware groups currently hitting government & defense
1 victim claimed in the current feed.
- ExfilSquad — 1 victim
Latest government & defense security news
- CISA shares advice on isolating vital systems during cyberattacks
- TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
- Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
- Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
- China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
- Google Cloud confirmed to offer a safer choice for EU public sector organizations with Dutch DPIA approval
Threat intelligence by sector
- Healthcare
- Financial Services
- Technology
- Manufacturing
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.