A threat group tracked by Microsoft targeting the energy sector.
Analyst brief
TERBIUM is a threat activity group tracked by Microsoft, linked to attacks against tens of thousands of computers in the energy sector in 2012. The group primarily targets organizations within the energy sector. It uses TTPs and tools that show similarities to its past operations, though specific details are not disclosed. Defenders should focus on detecting recurring attack patterns targeting the energy sector, especially those potentially aligning with historical indicators tied to this group.
TERBIUM
unknown
Microsoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to organizations in the energy sector. Microsoft Threat Intelligence refers to the activity group behind these attacks as TERBIUM, following our internal practice of assigning rogue actors chemical element names.
Which sector does the TERBIUM activity group primarily target?+
TERBIUM is a threat activity group tracked by Microsoft that primarily targets organizations in the energy sector.
What should defenders focus on regarding the TERBIUM group?+
Defenders should focus on detecting recurring attack patterns targeting the energy sector, especially those potentially aligning with historical indicators tied to the group's past operations that targeted tens of thousands of computers in 2012.