Threat actors targeting Manufacturing
Part of Threatwake, a free morning threat-intelligence dashboard.
26 threat actor groups tracked in MITRE ATT&CK are documented as targeting manufacturing, between them using 296 distinct ATT&CK techniques. 21 manufacturing victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against manufacturing
- T1105 · Ingress Tool Transfer (command-and-control) — used by 18 of 26 manufacturing actors (69%)
- T1588.002 · Tool (resource-development) — used by 17 of 26 manufacturing actors (65%)
- T1059.001 · PowerShell (execution) — used by 14 of 26 manufacturing actors (54%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 13 of 26 manufacturing actors (50%)
- T1027.013 · Encrypted/Encoded File (stealth) — used by 12 of 26 manufacturing actors (46%)
- T1078 · Valid Accounts (stealth) — used by 12 of 26 manufacturing actors (46%)
- T1204.002 · Malicious File (execution) — used by 12 of 26 manufacturing actors (46%)
- T1005 · Data from Local System (collection) — used by 11 of 26 manufacturing actors (42%)
- T1021.001 · Remote Desktop Protocol (lateral-movement) — used by 11 of 26 manufacturing actors (42%)
- T1059.003 · Windows Command Shell (execution) — used by 11 of 26 manufacturing actors (42%)
- T1190 · Exploit Public-Facing Application (initial-access) — used by 11 of 26 manufacturing actors (42%)
- T1016 · System Network Configuration Discovery (discovery) — used by 10 of 26 manufacturing actors (38%)
Threat actor groups
- Kimsuky (also: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) — 130 documented techniques
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- Scattered Spider (also: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944) — 64 documented techniques
- Threat Group-3390 (also: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION) — 57 documented techniques
- Dragonfly (also: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192) — 56 documented techniques
- Leviathan (also: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK) — 50 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- LAPSUS$ (also: DEV-0537, Strawberry Tempest) — 43 documented techniques
- MirrorFace (also: Earth Kasha) — 43 documented techniques
- Fox Kitten (also: UNC757, Parisite, Pioneer Kitten, RUBIDIUM) — 41 documented techniques
- BRONZE BUTLER (also: REDBALDKNIGHT, Tick) — 40 documented techniques
- APT-C-36 (also: Blind Eagle, TAG-144, AguilaCiega, APT-Q-98) — 38 documented techniques
- Aquatic Panda — 35 documented techniques
- APT42 — 32 documented techniques
- TA2541 — 28 documented techniques
- INC Ransom (also: GOLD IONIC) — 25 documented techniques
- APT19 (also: Codoso, C0d0so0, Codoso Team, Sunshop Group) — 21 documented techniques
- Axiom (also: Group 72) — 16 documented techniques
- APT18 (also: TG-0416, Dynamite Panda, Threat Group-0416) — 12 documented techniques
- Moses Staff (also: DEV-0500, Marigold Sandstorm) — 12 documented techniques
- Elderwood (also: Elderwood Gang, Beijing Group, Sneaky Panda) — 9 documented techniques
- POLONIUM (also: Plaid Rain) — 7 documented techniques
- Ajax Security Team (also: Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten) — 6 documented techniques
- Winnti Group (also: Blackfly) — 6 documented techniques
- SilverTerrier — 4 documented techniques
- TEMP.Veles (also: XENOTIME) — 0 documented techniques
Ransomware groups currently hitting manufacturing
21 victims claimed in the current feed.
- akira — 3 victims
- krybit — 2 victims
- medusalocker — 2 victims
- chaos — 2 victims
- clop — 2 victims
- emperador — 2 victims
- safepay — 2 victims
- securotrop — 1 victim
- Panzer — 1 victim
- play — 1 victim
- incransom — 1 victim
- Dark Project — 1 victim
Latest manufacturing security news
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
- Artifactory flaws chained in attacks deploying backdoor malware
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.