Axiom
Also reported as Group 72.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2010-0232 KEV
- CVE-2010-4398 KEV
- CVE-2011-2462 KEV
- CVE-2011-3402 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-1889 KEV
- CVE-2012-4792 KEV
- CVE-2013-3163 KEV
- CVE-2013-3893 KEV
- CVE-2013-3906 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
Show all 24 CVEs Show fewer
- CVE-2014-1761 KEV
- CVE-2014-4114 KEV
- CVE-2014-6352 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-2360 KEV
- CVE-2015-2424 KEV
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-5119 KEV
- CVE-2015-6585
- CVE-2015-7645 KEV ransomware
- CVE-2017-8759 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Axiom, Group 72 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Axiom, Group 72 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ZXShell (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Winnti Group, Wicked Panda - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti Group, Wicked Panda - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Blockbuster-Report
Show all 42 reports Show fewer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor What even is Winnti-
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor T1055 Process Injection
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Winnti
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor HELO Winnti_ Attack or Scan
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor HELO Winnti- Attack or Scan-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CN_APT-C-01
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Burning Umbrella
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New investigations into the CCleaner incident point to a possible third stage that had keylogger capacities
-
Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner part2
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Evidence Aurora Operation Still Active: Supply Chain Attack Through CCleaner part2
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Aurora_Operation_CCleaner_II
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evidence Aurora Operation Still Active Part 2- More Ties Uncovered Between CCleaner Hack & Chinese Hackers
-
The CCleaner Malware Fiasco Targeted at Least 18 Specific Tech Firms
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The CCleaner Malware Fiasco Targeted at Least 18 Specific Tech Firms
-
ICIT-Brief-China-Espionage-Dynasty
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ICIT-Brief-China-Espionage-Dynasty
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Please Read
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Blockbuster
-
Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups
-
Games are over- Winnti is now targeting pharmaceutical companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Games are over- Winnti is now targeting pharmaceutical companies
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Games are over - Securelist
-
The link to Mirror on Box failed its last check. Detailsfor WINNTI Analysis
-
The original link failed its last check. Original publisher Detailsfor WINNTI Analysis
-
Anthem Breach May Have Started in April 2014
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Anthem Breach May Have Started in April 2014
-
Cisco - Annual Security Report - 2015.pdf
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cisco - Annual Security Report - 2015.pdf
-
Threat Spotlight: Group 72, Opening the ZxShell
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Spotlight: Group 72, Opening the ZxShell
-
Microsoft Word - Executive Summary-Final.docx
The original link failed its last check. Original publisher Detailsfor Microsoft Word - Executive Summary-Final.docx
-
The link to Mirror on Box failed its last check. Detailsfor Operation SMN
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Spotlight: Group 72
Newest first. Details opens the report in Explore.