Commercial Facilities sector
61 groups observed targeting this sector
Commercial Facilities sector is targeted by both crime and nation-state actors
Groups targeting you25
- Earth LuscaunknownChina
- FIN8unknown
- incransomcrime
- LAPSUSunknown
- playcrime
- ShinyHuntersunknown
- TA505unknownRussia
- Storm-1567unknown
- APT41nation-stateChina
- AiLockcrime
- anubiscrime
- APT73unknown
- arcusmediacrime
- auroracrime
- blacknevascrime
- blackwatercrime
- BrainCiphercrime
- bravoxcrime
- chaoscrime
- clopcrime
- CMDOrganizationcrime
- CRPxOcrime
- cry0crime
- Dark Projectcrime
- Deadlockcrime
Most-used techniques25
Most-used TTPs include Valid Accounts (T1078), Ingress Tool Transfer (T1105), Archive via Utility (T1560.001), and Exploit Public-Facing Application (T1190). These techniques are primarily used for initial access, data transfer, and impact
- T1588.002Tool
- T1078Valid Accounts
- T1105Ingress Tool Transfer
- T1560.001Archive via Utility
- T1003.001LSASS Memory
- T1018Remote System Discovery
- T1021.001Remote Desktop Protocol
- T1036.005Match Legitimate Resource Name or Location
- T1133External Remote Services
- T1190Exploit Public-Facing Application
- T1486Data Encrypted for Impact
- T1657Financial Theft
- T1021.002SMB/Windows Admin Shares
- T1027.010Command Obfuscation
- T1059.003Windows Command Shell
- T1059.005Visual Basic
- T1068Exploitation for Privilege Escalation
- T1087.002Domain Account
- T1090Proxy
- T1112Modify Registry
- T1204.002Malicious File
- T1210Exploitation of Remote Services
- T1567.002Exfiltration to Cloud Storage
- T1583.001Domains
- T1685Disable or Modify Tools
Defense4
- 01
Ensure the security of public-facing applications
- 02
Monitor valid accounts and implement MFA
- 03
Use EDR solutions to detect anomalous activity on networks and systems
- 04
Strengthen security policies related to data archiving and transfer
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources — not a substitute for a tailored risk assessment.