Threat actors targeting Transportation
Part of Threatwake, a free morning threat-intelligence dashboard.
13 threat actor groups tracked in MITRE ATT&CK are documented as targeting transportation, between them using 194 distinct ATT&CK techniques. 2 transportation victims appear in the current ransomware leak-site feed.
Most-used ATT&CK techniques against transportation
- T1059.001 · PowerShell (execution) — used by 10 of 13 transportation actors (77%)
- T1105 · Ingress Tool Transfer (command-and-control) — used by 10 of 13 transportation actors (77%)
- T1204.002 · Malicious File (execution) — used by 10 of 13 transportation actors (77%)
- T1566.001 · Spearphishing Attachment (initial-access) — used by 9 of 13 transportation actors (69%)
- T1583.001 · Domains (resource-development) — used by 8 of 13 transportation actors (62%)
- T1588.002 · Tool (resource-development) — used by 8 of 13 transportation actors (62%)
- T1053.005 · Scheduled Task (execution) — used by 7 of 13 transportation actors (54%)
- T1078 · Valid Accounts (stealth) — used by 7 of 13 transportation actors (54%)
- T1547.001 · Registry Run Keys / Startup Folder (persistence) — used by 7 of 13 transportation actors (54%)
- T1021.001 · Remote Desktop Protocol (lateral-movement) — used by 6 of 13 transportation actors (46%)
- T1059.003 · Windows Command Shell (execution) — used by 6 of 13 transportation actors (46%)
- T1059.005 · Visual Basic (execution) — used by 6 of 13 transportation actors (46%)
Threat actor groups
- FIN7 (also: GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS) — 67 documented techniques
- Chimera — 59 documented techniques
- Dragonfly (also: TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192) — 56 documented techniques
- Leviathan (also: MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK) — 50 documented techniques
- menuPass (also: Cicada, POTASSIUM, Stone Panda, APT10) — 46 documented techniques
- Tropic Trooper (also: Pirate Panda, KeyBoy) — 40 documented techniques
- HEXANE (also: Lyceum, Siamesekitten, Spirlin) — 36 documented techniques
- APT33 (also: HOLMIUM, Elfin, Peach Sandstorm) — 31 documented techniques
- TA2541 — 28 documented techniques
- LazyScripter — 20 documented techniques
- CURIUM (also: Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc) — 19 documented techniques
- POLONIUM (also: Plaid Rain) — 7 documented techniques
- APT-C-23 (also: Mantis, Arid Viper, Desert Falcon, TAG-63) — 0 documented techniques
Ransomware groups currently hitting transportation
2 victims claimed in the current feed.
- CRPxO — 1 victim
- Deadlock — 1 victim
Threat intelligence by sector
- Healthcare
- Financial Services
- Government & Defense
- Technology
- Manufacturing
- Energy & Utilities
- Education
- Retail & E-Commerce
- Professional Services
- Agriculture & Food
- Hospitality
Actor and technique data is reference intelligence from MITRE ATT&CK v19.1 and the MISP galaxy — curated knowledge describing historically observed targeting, refreshed a few times a year. Ransomware and news are live feeds. Threatwake labels which is which throughout.