NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups G–I

14 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. GALLIUM (Granite Typhoon)

    G0093China31 techniques16 tools & malware

    GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions,…

  2. Gallmaker

    G00846 techniques

    Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has…

  3. Gamaredon Group (IRON TILDEN)

    G0047Russia70 techniques6 tools & malware3,028 live indicators

    Also tracked asPrimitive Bear · ACTINIUM · Armageddon and 4 more

    Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental…

  4. GCMAN

    G00362 techniques

    GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.

  5. GOLD SOUTHFIELD (Pinchy Spider)

    G01159 techniques2 tools & malware689 live indicators

    GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD…

  6. Gorgon Group

    G0078Pakistan16 techniques4 tools & malware3,284 live indicators

    Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has…

  7. Group5

    G0043Iran4 techniques2 tools & malware256 live indicators

    Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the…

  8. HAFNIUM (Operation Exchange Marauder)

    G0125China44 techniques6 tools & malware3 live indicators

    Also tracked asSilk Typhoon

    HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily…

  9. HEXANE (Lyceum)

    G1001Espionage36 techniques12 tools & malware57 live indicators

    Also tracked asSiamesekitten · Spirlin

    HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since…

  10. Higaisa

    G0126South Korea28 techniques3 tools & malware

    Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea;…

  11. INC Ransom (GOLD IONIC)

    G103225 techniques8 tools & malware

    INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July…

  12. Inception (Inception Framework)

    G0100RussiaEspionage22 techniques3 tools & malware

    Also tracked asCloud Atlas

    Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in…

  13. IndigoZebra

    G0136China7 techniques3 tools & malware

    IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.

  14. Indrik Spider (Evil Corp)

    G0119Russia33 techniques8 tools & malware1,009 live indicators

    Also tracked asManatee Tempest · DEV-0243 · UNC2165

    Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking…

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator