G0082

2019-01-29 • MITREAPT38

G0082 identifies a financially focused threat group whose documented operations target banks, venture-capital organizations, and other financial entities. Its tradecraft includes spearphishing with malicious attachments, watering-hole activity, counterfeit domains that imitate banks or investment firms, and the deployment of backdoors and web shells for persistent access. After compromise, the group collects host and user information, captures keystrokes and clipboard data, discovers network shares, and transfers files through custom tooling. In financial intrusions, it has manipulated databases and SWIFT-related records, altered printed or displayed transaction data, and used destructive tools to erase evidence or render systems inoperable. The group also employs packed implants, PowerShell, scheduled tasks, service creation, process injection, tunneling utilities, and secure deletion to execute commands, maintain access, move through networks, and frustrate investigation.

Related Actors

Related Reports in This Cluster

Top Authors

View G0082 reports only

View G0082 reports only