Poseidon Group is a Portuguese-speaking threat actor known for blackmailing victims into contracting them as a security firm using exfiltrated data.
Analyst brief
The Poseidon Group is a Portuguese-speaking threat group active since at least 2005, known for blackmailing victims by pressuring them to contract the group as a security firm using exfiltrated data. Their key TTPs include using PowerShell (T1059.001), masquerading as legitimate resources (T1036.005), and OS Credential Dumping (T1003). Defenders should focus on restricting PowerShell execution policies, monitoring anomalous process naming, and hardening access to LSASS memory against credential dumping attempts.
Poseidon Group
G0033
unknown
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm.