Gorgon Group
Also reported as Subaat, The Gorgon Group, ATK92, Pasty Gemini, ATK 92 and 2 other names. Linked to Pakistan by one source.
Reports per quarter
Techniques seen in the last two years
- T1059.001 7 reports in ATT&CK
- T1204.002 5 reports in ATT&CK
- T1566.001 5 reports in ATT&CK
- T1583.001 5 reports reports only
- T1027 4 reports reports only
- T1041 4 reports reports only
- T1583.003 4 reports reports only
- T1583.004 4 reports reports only
- T1027.010 3 reports reports only
- T1036 3 reports reports only
Show all 72 techniques Show fewer
- T1055.002 3 reports in ATT&CK
- T1071.001 3 reports reports only
- T1082 3 reports reports only
- T1105 3 reports in ATT&CK
- T1112 3 reports in ATT&CK
- T1566.002 3 reports reports only
- T1584.001 3 reports reports only
- T1620 3 reports reports only
- T1027.002 2 reports reports only
- T1047 2 reports reports only
- T1059.003 2 reports in ATT&CK
- T1059.007 2 reports reports only
- T1102 2 reports reports only
- T1190 2 reports reports only
- T1204.001 2 reports reports only
- T1219 2 reports reports only
- T1555.003 2 reports reports only
- T1583.008 2 reports reports only
- T1591 2 reports reports only
- T1591.002 2 reports reports only
- T1608.001 2 reports reports only
- T1657 2 reports reports only
- T1003 1 report reports only
- T1005 1 report reports only
- T1012 1 report reports only
- T1014 1 report reports only
- T1016 1 report reports only
- T1020 1 report reports only
- T1027.003 1 report reports only
- T1027.006 1 report reports only
- T1027.012 1 report reports only
- T1036.005 1 report reports only
- T1037.001 1 report reports only
- T1053.005 1 report reports only
- T1055 1 report reports only
- T1055.012 1 report in ATT&CK
- T1056.001 1 report reports only
- T1059.005 1 report in ATT&CK
- T1071 1 report reports only
- T1113 1 report reports only
- T1114 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1140 1 report in ATT&CK
- T1204 1 report reports only
- T1485 1 report reports only
- T1489 1 report reports only
- T1491 1 report reports only
- T1497.003 1 report reports only
- T1518.001 1 report reports only
- T1546.015 1 report reports only
- T1548.002 1 report reports only
- T1552.001 1 report reports only
- T1555 1 report reports only
- T1571 1 report reports only
- T1573.001 1 report reports only
- T1573.002 1 report reports only
- T1574.001 1 report reports only
- T1584.004 1 report reports only
- T1587.001 1 report reports only
- T1608.004 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2012-11882
- CVE-2012-5469
- CVE-2012-5687
- CVE-2013-0808
- CVE-2013-5947
- CVE-2014-0160 KEV
- CVE-2014-0346
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-2962
- CVE-2014-4019
Show all 94 CVEs Show fewer
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-2051 KEV
- CVE-2015-7036
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-9192
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-11822
- CVE-2017-11882 KEV ransomware
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-10561 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8570
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-8457
- CVE-2019-8577
- CVE-2019-8598
- CVE-2019-8600
- CVE-2019-8602
- CVE-2019-9489
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-10826
- CVE-2020-10827
- CVE-2020-11899 KEV
- CVE-2020-13756
- CVE-2020-1472 KEV ransomware
- CVE-2020-2021 KEV ransomware
- CVE-2020-7961 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-4044
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-41379 KEV ransomware
- CVE-2021-43936
- CVE-2021-44228 KEV ransomware
- CVE-2022-1096 KEV
- CVE-2022-24086 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2023-38331
- CVE-2023-38831 KEV ransomware
- CVE-2024-43451 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2025-0411 KEV
- CVE-2025-55182 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Transparent Tribe, APT 36 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Transparent Tribe, APT 36 - Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Gorgon Group - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Gorgon Group - Threat Group Cards: A Threat Actor Encyclopedia
-
Loki Password Stealer (PWS) (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Loki Password Stealer (PWS) (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Agent Tesla (Malware Family)
Show all 378 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Remcos (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor NjRAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
logpoint-etpr-a-comprehensive-overview-on-stealer-malware-families.pdf
The original link failed its last check. Original publisher Detailsfor logpoint-etpr-a-comprehensive-overview-on-stealer-malware-families.pdf
-
Spam trends campaigns senior superlatives 2023
The original link failed its last check. Original publisher Detailsfor Spam trends campaigns senior superlatives 2023
-
Evolving Info-Stealers: RedLine, Raccoon & New Threats
The original link failed its last check. Original publisher Detailsfor Evolving Info-Stealers: RedLine, Raccoon & New Threats
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
APT-C-58 (Gorgon Group) attack warning
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-58 (Gorgon Group) attack warning
-
2021 Gorgon Group APT Operation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 2021 Gorgon Group APT Operation
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT-C-56 (Transparent Tribe) Latest Attack Analysis and Associated Suspected Gorgon Group Attack Analysis Alert
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
InSideCopy: How this APT continues to evolve its arsenal
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor InSideCopy: How this APT continues to evolve its arsenal
-
The -WayBack” Campaign- a Large Scale Operation Hiding in Plain Sight
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The -WayBack” Campaign- a Large Scale Operation Hiding in Plain Sight
-
Catching RATs Over Custom Protocols Analysis of top non-HTTP-S threats
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Catching RATs Over Custom Protocols Analysis of top non-HTTP-S threats
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
The original link failed its last check. Original publisher Detailsfor https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/image-file-trickery-part-ii-fake-icon-delivers-nanocore/
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
https---www.ptsecurity.com-ww-en-analytics-antisandbox-techniques-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor https---www.ptsecurity.com-ww-en-analytics-antisandbox-techniques-
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Gorgon APT targeting MSME sector in India
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Gorgon APT targeting MSME sector in India
-
Gorgon APT targeting MSME sector in India
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Gorgon APT targeting MSME sector in India
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
analyses/RemcosDocDropper.MD at master · 1d8/analyses
The original link failed its last check. Original publisher Detailsfor analyses/RemcosDocDropper.MD at master · 1d8/analyses
-
CTNT_Q1_2020_COVID-Report_Final.pdf
The original link failed its last check. Original publisher Detailsfor CTNT_Q1_2020_COVID-Report_Final.pdf
-
The original link failed its last check. Original publisher Detailsfor Nanocore & CypherIT
-
TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
The original link failed its last check. Original publisher Detailsfor TA505's Box of Chocolate - On Hidden Gems packed with the TA505 Packer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Azorult loader stages
-
Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attribution is in the object- using RTF object dimensions to track APT phishing weaponizers
-
AZORult's End? Chrome Update Cripples Major Infostealer
The original link failed its last check. Original publisher Detailsfor AZORult's End? Chrome Update Cripples Major Infostealer
-
Exploring the Genesis Supply Chain for Fun and Profit
The original link failed its last check. Original publisher Detailsfor Exploring the Genesis Supply Chain for Fun and Profit
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
The original link failed its last check. Original publisher Detailsfor Binary Defense
-
Aggah Campaign- Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Aggah Campaign- Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
-
Aggah Campaign_ Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Aggah Campaign_ Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
The Enigmatic “Roma225” Campaign
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Enigmatic “Roma225” Campaign
-
The Gorgon Group: Slithering Between Nation State and Cybercrime
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Gorgon Group: Slithering Between Nation State and Cybercrime
-
Cyber-Espionage Campaign Targeting the Naval Industry (“MartyMcFly”)
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber-Espionage Campaign Targeting the Naval Industry (“MartyMcFly”)
-
The Gorgon Group- Slithering Between Nation State and Cybercrime
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Gorgon Group- Slithering Between Nation State and Cybercrime
-
Tracking Subaat Targeted Phishing Attack Leads to Threat Actors Repository
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking Subaat Targeted Phishing Attack Leads to Threat Actors Repository
-
Tracking Subaat- Targeted Phishing Attack Leads to Threat Actor’s Repository
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking Subaat- Targeted Phishing Attack Leads to Threat Actor’s Repository
-
Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's Repository
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor's Repository
-
The original link failed its last check. Original publisher Detailsfor GitHub - R3MRUM/loki-parse: A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security researchers who want to know what data is being exfiltrated to the C2, bot tracking, etc...
-
AutoIt-Compiled Worm Sends Fileless BLADABINDI/njRAT
The original link failed its last check. Original publisher Detailsfor AutoIt-Compiled Worm Sends Fileless BLADABINDI/njRAT
Newest first. Details opens the report in Explore.