SideCopy
G100816 documented techniques
Who is doing this, and how. Intrusion sets come from MITRE ATT&CK with the techniques each group is documented using, so a profile is a list of things to check rather than a description of something frightening. Extortion groups are counted from the victims they have named on their own leak sites.
16 documented techniques
16 documented techniques
15 documented techniques
15 documented techniques
Also known as Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda
15 documented techniques
Also known as Palmerworm
14 documented techniques
14 documented techniques
14 documented techniques
Also known as GOLD CABIN, Shathak
14 documented techniques
Also known as COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM
14 documented techniques
Also known as TA407, COBALT DICKENS
13 documented techniques
12 documented techniques
Also known as Silent Chollima, PLUTONIUM, Onyx Sleet
12 documented techniques
Also known as TG-0416, Dynamite Panda, Threat Group-0416
12 documented techniques
12 documented techniques
12 documented techniques
12 documented techniques
Also known as DEV-0500, Marigold Sandstorm
12 documented techniques
Also known as DEV-0206, TA569, GOLD PRELUDE, UNC1543
12 documented techniques
11 documented techniques
11 documented techniques
11 documented techniques
Also known as APT-C-43, El Machete
11 documented techniques
11 documented techniques
Intrusion set data is from MITRE ATT&CK, which is maintained by MITRE and released for public use. Extortion group activity is derived from this tracker’s own incident records, sourced from RansomLook under CC BY 4.0.