Threat groups G–I
14 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.
GALLIUM (Granite Typhoon)
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions,…
Gallmaker
Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has…
Gamaredon Group (IRON TILDEN)
Also tracked asPrimitive Bear · ACTINIUM · Armageddon and 4 more
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental…
GCMAN
GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.
GOLD SOUTHFIELD (Pinchy Spider)
GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD…
Gorgon Group
Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has…
Group5
Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the…
HAFNIUM (Operation Exchange Marauder)
Also tracked asSilk Typhoon
HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily…
HEXANE (Lyceum)
Also tracked asSiamesekitten · Spirlin
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since…
Higaisa
Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea;…
INC Ransom (GOLD IONIC)
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July…
Inception (Inception Framework)
Also tracked asCloud Atlas
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in…
IndigoZebra
IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.
Indrik Spider (Evil Corp)
Also tracked asManatee Tempest · DEV-0243 · UNC2165
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking…
Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator