Threat actors targeting Professional Services
Part of Threatwake, a free morning threat-intelligence dashboard.
35 threat actor groups tracked in MITRE ATT&CK are documented as targeting professional services, between them using 353 distinct ATT&CK techniques. 12 professional services victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against professional services
- T1059.001 · PowerShell (execution) — used by 22 of 35 professional services actors (63%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 21 of 35 professional services actors (60%)
- T1082 · System Information Discovery (discovery) — used by 20 of 35 professional services actors (57%)
- T1204.002 · Malicious File (execution) — used by 20 of 35 professional services actors (57%)
- T1588.002 · Tool (resource-development) — used by 20 of 35 professional services actors (57%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 19 of 35 professional services actors (54%)
- T1005 · Data from Local System (collection) — used by 16 of 35 professional services actors (46%)
- T1053.005 · Scheduled Task (execution) — used by 16 of 35 professional services actors (46%)
- T1059.003 · Windows Command Shell (execution) — used by 16 of 35 professional services actors (46%)
- T1071.001 · Web Protocols (command-and-control) — used by 16 of 35 professional services actors (46%)
- T1033 · System Owner/User Discovery (discovery) — used by 15 of 35 professional services actors (43%)
- T1204.001 · Malicious Link (execution) — used by 15 of 35 professional services actors (43%)
Threat actor groups
- Kimsuky (also: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM) — 130 documented techniques
- Mustang Panda (also: TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS) — 85 documented techniques
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- APT32 (also: SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone) — 78 documented techniques
- Magic Hound (also: TA453, COBALT ILLUSION, Charming Kitten, ITG18) — 78 documented techniques
- Gamaredon Group (also: IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon) — 70 documented techniques
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- APT29 (also: IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) — 66 documented techniques
- VOID MANTICORE (also: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma) — 63 documented techniques
- Earth Lusca (also: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX) — 44 documented techniques
- HAFNIUM (also: Operation Exchange Marauder, Silk Typhoon) — 44 documented techniques
- LAPSUS$ (also: DEV-0537, Strawberry Tempest) — 43 documented techniques
- MirrorFace (also: Earth Kasha) — 43 documented techniques
- Patchwork (also: Hangover Group, Dropping Elephant, Chinastrats, MONSOON) — 41 documented techniques
- Aquatic Panda — 35 documented techniques
- APT42 — 32 documented techniques
- APT37 (also: InkySquid, ScarCruft, Reaper, Group123) — 29 documented techniques
- Winter Vivern (also: TA473, UAC-0114) — 27 documented techniques
- Play — 26 documented techniques
- WIRTE (also: Ashen Lepus) — 26 documented techniques
- APT19 (also: Codoso, C0d0so0, Codoso Team, Sunshop Group) — 21 documented techniques
- Star Blizzard (also: SEABORGIUM, Callisto Group, TA446, COLDRIVER) — 20 documented techniques
- CURIUM (also: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc) — 19 documented techniques
- Daggerfly (also: Evasive Panda, BRONZE HIGHLAND) — 17 documented techniques
- Axiom (also: Group 72) — 16 documented techniques
- Molerats (also: Operation Molerats, Gaza Cybergang) — 16 documented techniques
- Stealth Falcon — 16 documented techniques
- BlackTech (also: Palmerworm) — 14 documented techniques
- APT18 (also: TG-0416, Dynamite Panda, Threat Group-0416) — 12 documented techniques
- Elderwood (also: Elderwood Gang, Beijing Group, Sneaky Panda) — 9 documented techniques
- Winnti Group (also: Blackfly) — 6 documented techniques
- APT12 (also: IXESHE, DynCalc, Numbered Panda, DNSCALC) — 5 documented techniques
- APT17 (also: Deputy Dog) — 2 documented techniques
- BlackOasis — 1 documented techniques
- APT-C-23 (also: Mantis, Arid Viper, Desert Falcon, TAG-63) — 0 documented techniques
Ransomware groups currently hitting professional services
12 victims claimed in the current feed.
- CRPxO — 4 victims
- Global Secret Group — 3 victims
- qilin — 2 victims
- m3rx — 2 victims
- safepay — 1 victim
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Manufacturing
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.