NEW: Group Profiler — instant APT intel lookup. Try it →

Threat Group-1314

Also known as: TG-1314

Overview

Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.

Naming & attribution

Threat Group-1314 is tracked under 2 names across the industry. It uses 4 documented ATT&CK techniques — more than 9% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
TG-1314Dell SecureWorks Counter Threat Unit Special Operations Team

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Cinnamon Tempest China — 3 shared techniques (15% overlap)
  • ToddyCat — 3 shared techniques (12% overlap)
  • Play — 3 shared techniques (11% overlap)
  • Aquatic Panda China — 3 shared techniques (8% overlap)
  • APT3 China — 3 shared techniques (7% overlap)
  • BlackByte — 3 shared techniques (6% overlap)

TTPs — 4 techniques across 3 tactics

Stealth

Lateral Movement

Tools & malware (2)

Net · PsExec

Reporting (1)