Communications sector
26 groups observed targeting this sector
The Communications sector is primarily targeted by nation-state actors and some unknown actors.
Groups targeting you25
- APT42nation-stateIran
- APT5unknownChina
- Earth LuscaunknownChina
- LYCEUMnation-stateIran
- OilRignation-stateIran
- WIZARD SPIDERnation-stateRussia
- Tortoiseshellnation-stateIran
- BackdoorDiplomacyunknown
- Moleratsnation-statePalestine
- PLATINUMunknown
- APT18nation-stateChina
- Aoqin DragonunknownChina
- APT41nation-stateChina
- AridVipernation-statePalestine
- BANISHED KITTENnation-stateIran
- BRONZE SPRINGunknownChina
- Cotton Sandstormnation-stateIran
- DAGGER PANDAnation-stateChina
- FOXY PANDAunknownChina
- HURRICANE PANDAunknownChina
- Longhornnation-stateUSA
- NoName057(16)unknown
- RedGolfnation-stateChina
- Sandman APTnation-stateChina
- TianWunation-stateChina
Most-used techniques25
The most-used TTPs include Ingress Tool Transfer (T1105), System Information Discovery (T1082), Malicious File (T1204.002), and Spearphishing (T1566.001, T1566.002). These techniques are primarily used to gain initial access, discover systems, and exfiltrate data.
- T1105Ingress Tool Transfer
- T1003.001LSASS Memory
- T1082System Information Discovery
- T1204.002Malicious File
- T1021.001Remote Desktop Protocol
- T1036Masquerading
- T1036.005Match Legitimate Resource Name or Location
- T1056.001Keylogging
- T1057Process Discovery
- T1059.001PowerShell
- T1059.003Windows Command Shell
- T1083File and Directory Discovery
- T1189Drive-by Compromise
- T1505.003Web Shell
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1583.001Domains
- T1588.002Tool
- T1005Data from Local System
- T1016System Network Configuration Discovery
- T1046Network Service Discovery
- T1048.003Exfiltration Over Unencrypted Non-C2 Protocol
- T1053.005Scheduled Task
- T1059.005Visual Basic
- T1068Exploitation for Privilege Escalation
Defense5
- 01
Implementing EDR solutions to detect unusual activity on networks and systems
- 02
Conducting Spearphishing simulations and training to enhance security awareness
- 03
Implementing MFA to restrict especially RDP (T1021.001) and other remote access
- 04
Regularly updating and securing system and network configurations
- 05
Conducting continuous monitoring for malicious software and vulnerabilities
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources โ not a substitute for a tailored risk assessment.