G0001A defensive guide to the Enterprise ATT&CK activity-cluster record G0001, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Chinese espionage cluster reported against aerospace, defense, government, manufacturing, and media sectors.
Open profile →G0009A defensive guide to the Enterprise ATT&CK activity-cluster record G0009, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Chinese cluster reported against government, defense, financial, healthcare, and telecommunications targets, with overlap ambiguity in public reporting.
Open profile →G0012A defensive guide to the Enterprise ATT&CK activity-cluster record G0012, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected South Korean cluster reported in East Asian espionage operations involving hotel networks, spearphishing, and file-sharing networks.
Open profile →G0018A defensive guide to the Enterprise ATT&CK activity-cluster record G0018, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a China-based activity cluster reported against organizations involved in financial, economic, and trade policy, often using publicly available remote-access tools.
Open profile →G0035A defensive guide to the Enterprise ATT&CK activity-cluster record G0035, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a cyber-espionage cluster attributed to Russia’s FSB Center 16 and reported against industrial-control and critical-infrastructure sectors.
Open profile →G0047A defensive guide to the Enterprise ATT&CK activity-cluster record G0047, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Russian and FSB-linked cluster reported in persistent operations focused on Ukraine.
Open profile →G0070A defensive guide to the Enterprise ATT&CK activity-cluster record G0070, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an activity cluster attributed in public reporting to the Lebanese General Directorate of General Security and active since at least 2012.
Open profile →G0079A defensive guide to the Enterprise ATT&CK activity-cluster record G0079, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a cluster reported against government agencies and educational institutions in the Middle East using open-source tools and custom payloads.
Open profile →G0087A defensive guide to the Enterprise ATT&CK activity-cluster record G0087, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing Iranian Ministry of Intelligence and Security-linked espionage activity reported across travel, hospitality, academia, and telecommunications.
Open profile →G0093A defensive guide to the Enterprise ATT&CK activity-cluster record G0093, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a likely China-based cyber-espionage cluster reported against telecommunications, finance, and government organizations.
Open profile →G0096A defensive guide to the Enterprise ATT&CK activity-cluster record G0096, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a China-sponsored espionage cluster also reported conducting financially motivated operations across many sectors.
Open profile →G0105A defensive guide to the Enterprise ATT&CK activity-cluster record G0105, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a financially motivated cluster reported against financial institutions in Eastern Europe.
Open profile →G0117A defensive guide to the Enterprise ATT&CK activity-cluster record G0117, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Iranian-nexus cluster reported across multiple sectors and regions.
Open profile →G0125A defensive guide to the Enterprise ATT&CK activity-cluster record G0125, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a likely China state-sponsored cluster reported against a broad range of United States sectors.
Open profile →G0130A defensive guide to the Enterprise ATT&CK activity-cluster record G0130, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an Iran-linked cluster active since at least 2010 that shifted from website defacement toward malware-based espionage.
Open profile →G0135A defensive guide to the Enterprise ATT&CK activity-cluster record G0135, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an espionage cluster active since at least 2017 and reported against foreign ministries and telecommunications companies.
Open profile →G0138A defensive guide to the Enterprise ATT&CK activity-cluster record G0138, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a North Korean state-sponsored cluster associated with destructive and financially motivated activity, with acknowledged overlap in public naming.
Open profile →G0143A defensive guide to the Enterprise ATT&CK activity-cluster record G0143, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected China-based cluster with intelligence-collection and industrial-espionage missions against telecommunications, technology, and government entities.
Open profile →G1000A defensive guide to the Enterprise ATT&CK activity-cluster record G1000, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Russian espionage cluster reported against electric utilities in the United States and United Kingdom.
Open profile →G1002A defensive guide to the Enterprise ATT&CK activity-cluster record G1002, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected South Asian espionage cluster reported against government, energy, and engineering organizations.
Open profile →G1007A defensive guide to the Enterprise ATT&CK activity-cluster record G1007, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected China-based espionage cluster reported against government, education, and telecommunications organizations in Southeast Asia and nearby regions.
Open profile →G1015A defensive guide to the Enterprise ATT&CK activity-cluster record G1015, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an English-speaking cybercriminal cluster reported to rely heavily on social engineering, identity compromise, and cloud access.
Open profile →G1023A defensive guide to the Enterprise ATT&CK activity-cluster record G1023, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a China-based espionage actor reported against telecommunications, aerospace, and defense organizations, including networking devices.
Open profile →G1027A defensive guide to the Enterprise ATT&CK activity-cluster record G1027, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a suspected Iranian IRGC-affiliated cluster reported in PLC and HMI targeting and device-interface defacement.
Open profile →G1028A defensive guide to the Enterprise ATT&CK activity-cluster record G1028, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a cluster active since at least 2014 with a Middle East focus and reported development of Android and iOS spyware.
Open profile →G1030A defensive guide to the Enterprise ATT&CK activity-cluster record G1030, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an Iranian activity cluster reported in ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.
Open profile →G1034A defensive guide to the Enterprise ATT&CK activity-cluster record G1034, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a PRC-linked advanced persistent threat cluster reported against individuals, governments, NGOs, and telecommunications companies.
Open profile →G1043A defensive guide to the Enterprise ATT&CK activity-cluster record G1043, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a ransomware activity cluster operating since at least 2021 and associated with multiple BlackByte ransomware versions.
Open profile →G1044A defensive guide to the Enterprise ATT&CK activity-cluster record G1044, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing an Iranian-sponsored espionage and surveillance cluster reported to use spearphishing, mobile malware, native features, and open-source tools.
Open profile →G1049A defensive guide to the Enterprise ATT&CK activity-cluster record G1049, including naming overlap, evidence, behavior relationships, and attribution confidence. The official record summarizes public reporting describing a DPRK-linked revenue-generating cluster reported against the cryptocurrency sector and associated with the 3CX supply-chain campaign.
Open profile →