Threat Group-1314
Also known as: TG-1314
Overview
Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.
Naming & attribution
Threat Group-1314 is tracked under 2 names across the industry. It uses 4 documented ATT&CK techniques — more than 9% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| TG-1314 | Dell SecureWorks Counter Threat Unit Special Operations Team |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- Cinnamon Tempest China — 3 shared techniques (15% overlap)
- ToddyCat — 3 shared techniques (12% overlap)
- Play — 3 shared techniques (11% overlap)
- Aquatic Panda China — 3 shared techniques (8% overlap)
- APT3 China — 3 shared techniques (7% overlap)
- BlackByte — 3 shared techniques (6% overlap)
TTPs — 4 techniques across 3 tactics
Execution
-
T1059.003Windows Command Shell -
T1072Software Deployment Tools
Stealth
-
T1078.002Domain Accounts
Lateral Movement
-
T1021.002SMB/Windows Admin Shares
Tools & malware (2)
Net · PsExec
Reporting (1)
- Living off the Land — Dell SecureWorks Counter Threat Unit Special Operations Team