Critical Manufacturing sector
79 groups observed targeting this sector
Critical Manufacturing sector is targeted by nation-state sponsored (APT42, OilRig, Sandworm, Tick, POLONIUM, APT41) and crime (incransom, play, AiLock, anubis, arcusmedia, aurora, Barracuda, Black X, Blackfield, blacknevas, BrainCipher, chaos) actors.
Groups targeting you25
- APT42nation-stateIran
- incransomcrime
- OilRignation-stateIran
- playcrime
- Sandwormnation-stateRussia
- ShinyHuntersunknown
- Ticknation-stateChina
- Storm-1567unknown
- APT-C-36unknown
- POLONIUMnation-stateLebanon
- APT41nation-stateChina
- AiLockcrime
- anubiscrime
- APT73unknown
- arcusmediacrime
- auroracrime
- Barracudacrime
- Black Xcrime
- Blackfieldcrime
- blacknevascrime
- Booba Projectunknown
- BrainCiphercrime
- BRONZE SPRINGunknownChina
- BRONZE VAPORunknownChina
- chaoscrime
Most-used techniques25
Most-used TTPs include Ingress Tool Transfer (T1105), External Remote Services (T1133), Exploit Public-Facing Application (T1190), Tool (T1588.002), and Valid Accounts (T1078). These techniques are primarily used for initial access, discovery, and data theft.
- T1105Ingress Tool Transfer
- T1133External Remote Services
- T1190Exploit Public-Facing Application
- T1588.002Tool
- T1003.001LSASS Memory
- T1018Remote System Discovery
- T1021.001Remote Desktop Protocol
- T1036.005Match Legitimate Resource Name or Location
- T1059.001PowerShell
- T1059.003Windows Command Shell
- T1078Valid Accounts
- T1132.001Standard Encoding
- T1566.002Spearphishing Link
- T1583.001Domains
- T1657Financial Theft
- T1685Disable or Modify Tools
- T1005Data from Local System
- T1016System Network Configuration Discovery
- T1021.002SMB/Windows Admin Shares
- T1027.010Command Obfuscation
- T1046Network Service Discovery
- T1047Windows Management Instrumentation
- T1059.005Visual Basic
- T1070.004File Deletion
- T1082System Information Discovery
Defense5
- 01
Ensure the security of public-facing applications
- 02
Restrict and monitor remote access
- 03
Limit network and system discovery
- 04
Strengthen security tools and processes
- 05
Implement MFA and ensure strong authentication
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources โ not a substitute for a tailored risk assessment.