Threat actors targeting Hospitality
Part of Threatwake, a free morning threat-intelligence dashboard.
14 threat actor groups tracked in MITRE ATT&CK are documented as targeting hospitality, between them using 239 distinct ATT&CK techniques. 4 hospitality victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against hospitality
- T1059.001 · PowerShell (execution) — used by 12 of 14 hospitality actors (86%)
- T1588.002 · Tool (resource-development) — used by 12 of 14 hospitality actors (86%)
- T1059.003 · Windows Command Shell (execution) — used by 10 of 14 hospitality actors (71%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 10 of 14 hospitality actors (71%)
- T1204.002 · Malicious File (execution) — used by 10 of 14 hospitality actors (71%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 9 of 14 hospitality actors (64%)
- T1003.001 · LSASS Memory (credential-access) — used by 8 of 14 hospitality actors (57%)
- T1005 · Data from Local System (collection) — used by 8 of 14 hospitality actors (57%)
- T1053.005 · Scheduled Task (execution) — used by 8 of 14 hospitality actors (57%)
- T1070.004 · File Deletion (stealth) — used by 8 of 14 hospitality actors (57%)
- T1082 · System Information Discovery (discovery) — used by 8 of 14 hospitality actors (57%)
- T1140 · Deobfuscate/Decode Files or Information (stealth) — used by 8 of 14 hospitality actors (57%)
Threat actor groups
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- Scattered Spider (also: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944) — 64 documented techniques
- Threat Group-3390 (also: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION) — 57 documented techniques
- APT38 (also: NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima) — 56 documented techniques
- APT39 (also: ITG07, Chafer, Remix Kitten) — 53 documented techniques
- FIN13 (also: Elephant Beetle) — 53 documented techniques
- Earth Lusca (also: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX) — 44 documented techniques
- RedCurl — 41 documented techniques
- FIN6 (also: Magecart Group 6, ITG08, Skeleton Spider, TAAL) — 40 documented techniques
- FIN8 (also: Syssphinx) — 36 documented techniques
- Aquatic Panda — 35 documented techniques
- TA505 (also: Hive0065, Spandex Tempest, CHIMBORAZO) — 34 documented techniques
- Darkhotel (also: DUBNIUM, Zigzag Hail) — 24 documented techniques
- FIN5 — 11 documented techniques
Ransomware groups currently hitting hospitality
4 victims claimed in the current feed.
- dragonforce — 1 victim
- incransom — 1 victim
- anubis — 1 victim
- Global Secret Group — 1 victim
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Manufacturing
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.