Threat actors targeting Technology
Part of Threatwake, a free morning threat-intelligence dashboard.
51 threat actor groups tracked in MITRE ATT&CK are documented as targeting technology, between them using 373 distinct ATT&CK techniques. 20 technology victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against technology
- T1059.001 · PowerShell (execution) — used by 33 of 51 technology actors (65%)
- T1588.002 · Tool (resource-development) — used by 32 of 51 technology actors (63%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 30 of 51 technology actors (59%)
- T1059.003 · Windows Command Shell (execution) — used by 24 of 51 technology actors (47%)
- T1204.002 · Malicious File (execution) — used by 24 of 51 technology actors (47%)
- T1036.005 · Match Legitimate Resource Name or Location (stealth) — used by 21 of 51 technology actors (41%)
- T1071.001 · Web Protocols (command-and-control) — used by 21 of 51 technology actors (41%)
- T1003.001 · LSASS Memory (credential-access) — used by 20 of 51 technology actors (39%)
- T1070.004 · File Deletion (stealth) — used by 20 of 51 technology actors (39%)
- T1078 · Valid Accounts (stealth) — used by 20 of 51 technology actors (39%)
- T1190 · Exploit Public-Facing Application (initial-access) — used by 20 of 51 technology actors (39%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 20 of 51 technology actors (39%)
Threat actor groups
- APT41 (also: Wicked Panda, Brass Typhoon, BARIUM) — 82 documented techniques
- Volt Typhoon (also: BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236) — 81 documented techniques
- Sandworm Team (also: ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group)) — 79 documented techniques
- OilRig (also: COBALT GYPSY, IRN2, APT34, Helix Kitten) — 76 documented techniques
- MuddyWater (also: Earth Vetala, MERCURY, Static Kitten, Seedworm) — 68 documented techniques
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- Scattered Spider (also: Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944) — 64 documented techniques
- Wizard Spider (also: UNC1878, TEMP.MixMaster, Grim Spider, FIN12) — 64 documented techniques
- VOID MANTICORE (also: COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma) — 63 documented techniques
- Chimera — 59 documented techniques
- Medusa Group — 57 documented techniques
- Threat Group-3390 (also: Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION) — 57 documented techniques
- Contagious Interview (also: DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER) — 54 documented techniques
- APT39 (also: ITG07, Chafer, Remix Kitten) — 53 documented techniques
- UNC3886 — 49 documented techniques
- Ember Bear (also: UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard) — 47 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- Earth Lusca (also: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX) — 44 documented techniques
- HAFNIUM (also: Operation Exchange Marauder, Silk Typhoon) — 44 documented techniques
- LAPSUS$ (also: DEV-0537, Strawberry Tempest) — 43 documented techniques
- Fox Kitten (also: UNC757, Parisite, Pioneer Kitten, RUBIDIUM) — 41 documented techniques
- BRONZE BUTLER (also: REDBALDKNIGHT, Tick) — 40 documented techniques
- Tropic Trooper (also: Pirate Panda, KeyBoy) — 40 documented techniques
- FIN8 (also: Syssphinx) — 36 documented techniques
- HEXANE (also: Lyceum, Siamesekitten, Spirlin) — 36 documented techniques
- Aquatic Panda — 35 documented techniques
- APT42 — 32 documented techniques
- GALLIUM (also: Granite Typhoon) — 31 documented techniques
- APT5 (also: Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda) — 29 documented techniques
- WIRTE (also: Ashen Lepus) — 26 documented techniques
- APT19 (also: Codoso, C0d0so0, Codoso Team, Sunshop Group) — 21 documented techniques
- CURIUM (also: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc) — 19 documented techniques
- Daggerfly (also: Evasive Panda, BRONZE HIGHLAND) — 17 documented techniques
- BackdoorDiplomacy — 15 documented techniques
- Tonto Team (also: Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda) — 15 documented techniques
- BlackTech (also: Palmerworm) — 14 documented techniques
- Salt Typhoon — 14 documented techniques
- APT18 (also: TG-0416, Dynamite Panda, Threat Group-0416) — 12 documented techniques
- Machete (also: APT-C-43, El Machete) — 11 documented techniques
- Deep Panda (also: Shell Crew, WebMasters, KungFu Kittens, PinkPanther) — 10 documented techniques
Ransomware groups currently hitting technology
20 victims claimed in the current feed.
- Global Secret Group — 9 victims
- CRPxO — 5 victims
- Deadlock — 2 victims
- chaos — 1 victim
- Booba Project — 1 victim
- shinyhunters — 1 victim
- ExfilSquad — 1 victim
Latest technology security news
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Manufacturing
- Energy & Utilities
- Education
- Retail & E-Commerce
- Transportation
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.