Threat actors targeting Manufacturing
Part of Threatwake, a free morning threat-intelligence dashboard.
26 threat actor groups tracked in MITRE ATT&CK are documented as targeting manufacturing, between them using 296 distinct ATT&CK techniques. 13 manufacturing victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against manufacturing
- T1105 · Ingress Tool Transfer (command-and-control) — used by 18 of 26 manufacturing actors (69%)
- T1588.002 · Tool (resource-development) — used by 17 of 26 manufacturing actors (65%)
- T1059.001 · PowerShell (execution) — used by 14 of 26 manufacturing actors (54%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 13 of 26 manufacturing actors (50%)
- T1027.013 · Encrypted/Encoded File (stealth) — used by 12 of 26 manufacturing actors (46%)
- T1078 · Valid Accounts (stealth) — used by 12 of 26 manufacturing actors (46%)
- T1204.002 · Malicious File (execution) — used by 12 of 26 manufacturing actors (46%)
- T1005 · Data from Local System (collection) — used by 11 of 26 manufacturing actors (42%)
- T1021.001 · Remote Desktop Protocol (lateral-movement) — used by 11 of 26 manufacturing actors (42%)
- T1059.003 · Windows Command Shell (execution) — used by 11 of 26 manufacturing actors (42%)
- T1190 · Exploit Public-Facing Application (initial-access) — used by 11 of 26 manufacturing actors (42%)
- T1016 · System Network Configuration Discovery (discovery) — used by 10 of 26 manufacturing actors (38%)
Threat actor groups
- Kimsuky (also: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) — 130 documented techniques
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- Scattered Spider (also: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944) — 64 documented techniques
- Threat Group-3390 (also: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION) — 57 documented techniques
- Dragonfly (also: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192) — 56 documented techniques
- Leviathan (also: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK) — 50 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- LAPSUS$ (also: DEV-0537, Strawberry Tempest) — 43 documented techniques
- MirrorFace (also: Earth Kasha) — 43 documented techniques
- Fox Kitten (also: UNC757, Parisite, Pioneer Kitten, RUBIDIUM) — 41 documented techniques
- BRONZE BUTLER (also: REDBALDKNIGHT, Tick) — 40 documented techniques
- APT-C-36 (also: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98) — 38 documented techniques
- Aquatic Panda — 35 documented techniques
- APT42 — 32 documented techniques
- TA2541 — 28 documented techniques
- INC Ransom (also: GOLD IONIC) — 25 documented techniques
- APT19 (also: Codoso, C0d0so0, Codoso Team, Sunshop Group) — 21 documented techniques
- Axiom (also: Group 72) — 16 documented techniques
- APT18 (also: TG-0416, Dynamite Panda, Threat Group-0416) — 12 documented techniques
- Moses Staff (also: DEV-0500, Marigold Sandstorm) — 12 documented techniques
- Elderwood (also: Elderwood Gang, Beijing Group, Sneaky Panda) — 9 documented techniques
- POLONIUM (also: Plaid Rain) — 7 documented techniques
- Ajax Security Team (also: Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten) — 6 documented techniques
- Winnti Group (also: Blackfly) — 6 documented techniques
- SilverTerrier — 4 documented techniques
- TEMP.Veles (also: XENOTIME) — 0 documented techniques
Ransomware groups currently hitting manufacturing
13 victims claimed in the current feed.
- Global Secret Group — 3 victims
- incransom — 2 victims
- ExfilSquad — 2 victims
- thegentlemen — 1 victim
- cmdorganization — 1 victim
- Deadlock — 1 victim
- Booba Project — 1 victim
- CRPxO — 1 victim
- m3rx — 1 victim
Latest manufacturing security news
- OpenAI models used Artifactory zero-days to escape to the internet
- JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.