Contagious Interview
G1052Also known as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER
54 documented techniques
Who is doing this, and how. Intrusion sets come from MITRE ATT&CK with the techniques each group is documented using, so a profile is a list of things to check rather than a description of something frightening. Extortion groups are counted from the victims they have named on their own leak sites.
Also known as DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER
54 documented techniques
Also known as ITG07, Chafer, Remix Kitten
53 documented techniques
Also known as Elephant Beetle
53 documented techniques
Also known as MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK
50 documented techniques
49 documented techniques
Also known as Hecamede
48 documented techniques
Also known as UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard
47 documented techniques
Also known as APT15, Mirage, Vixen Panda, GREF
46 documented techniques
Also known as Cicada, POTASSIUM, Stone Panda, APT10
46 documented techniques
Also known as UNC6240, Bling Libra
46 documented techniques
Also known as Gothic Panda, Pirpi, UPS Team, Buckeye
44 documented techniques
Also known as TAG-22, Charcoal Typhoon, CHROMIUM, ControlX
44 documented techniques
Also known as Operation Exchange Marauder, Silk Typhoon
44 documented techniques
Also known as DEV-0537, Strawberry Tempest
43 documented techniques
Also known as Earth Kasha
43 documented techniques
42 documented techniques
Also known as UNC757, Parisite, Pioneer Kitten, RUBIDIUM
41 documented techniques
Also known as Hangover Group, Dropping Elephant, Chinastrats, MONSOON
41 documented techniques
41 documented techniques
Also known as REDBALDKNIGHT, Tick
40 documented techniques
Also known as Magecart Group 6, ITG08, Skeleton Spider, TAAL
40 documented techniques
Also known as Pirate Panda, KeyBoy
40 documented techniques
Also known as Blind Eagle, TAG-144, AguilaCiega, APT-Q-98
38 documented techniques
Also known as Syssphinx
36 documented techniques
Intrusion set data is from MITRE ATT&CK, which is maintained by MITRE and released for public use. Extortion group activity is derived from this tracker’s own incident records, sourced from RansomLook under CC BY 4.0.