Gorgon Group
Overview
Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States.
Naming & attribution
Gorgon Group is tracked under 1 names across the industry. It uses 16 documented ATT&CK techniques — more than 45% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Gorgon Group | Falcone, R., et al |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1055.002Portable Executable Injection — used by 2 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Nomadic Octopus Russia — 6 shared techniques (35% overlap)
- Silence — 10 shared techniques (29% overlap)
- TA505 — 11 shared techniques (28% overlap)
- APT19 China — 8 shared techniques (28% overlap)
- Molerats — 7 shared techniques (28% overlap)
- DarkHydrus — 5 shared techniques (28% overlap)
Malware families with current indicators
2 families attributed to Gorgon Group, carrying 3,220 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- Remcos 2,964 indicators
- NanoCore 256 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
TTPs — 16 techniques across 7 tactics
Resource Development
-
T1588.002Tool
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1059.001PowerShell -
T1059.003Windows Command Shell -
T1059.005Visual Basic -
T1106Native API -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder -
T1547.009Shortcut Modification
Stealth
-
T1055.002Portable Executable Injection -
T1055.012Process Hollowing -
T1140Deobfuscate/Decode Files or Information -
T1564.003Hidden Window
Defense Impairment
-
T1112Modify Registry -
T1685Disable or Modify Tools
Command and Control
-
T1105Ingress Tool Transfer
Tools & malware (4)
NanoCore · QuasarRAT · Remcos · njRAT
Reporting (1)
- The Gorgon Group: Slithering Between Nation State and Cybercrime — Falcone, R., et al