Poseidon Group
Overview
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm.
Naming & attribution
Poseidon Group is tracked under 1 names across the industry. It uses 8 documented ATT&CK techniques — more than 24% of the 174 groups tracked here. Activity attributed since at least 2005.
| Name | First reported by |
|---|---|
| Poseidon Group | Kaspersky Lab's Global Research and Analysis Team |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
TTPs — 8 techniques across 4 tactics
Execution
-
T1059.001PowerShell
Stealth
Credential Access
-
T1003OS Credential Dumping
Discovery
-
T1007System Service Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1087.001Local Account -
T1087.002Domain Account
Reporting (1)
- Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionage — Kaspersky Lab's Global Research and Analysis Team