Defense Industrial Base sector
47 groups observed targeting this sector
The Defense Industrial Base is primarily targeted by nation-state APT groups, although some unknown groups are also active.
Groups targeting you25
- APT27unknownChina
- APT28nation-stateRussia
- APT42nation-stateIran
- Kimsukynation-stateNorth Korea
- LYCEUMnation-stateIran
- QUILTED TIGERnation-stateIndia
- RAZOR TIGERnation-stateIndia
- Turlanation-stateRussia
- WIZARD SPIDERnation-stateRussia
- APT23unknownChina
- APT17nation-stateChina
- APT19nation-stateChina
- ToddyCatunknown
- CallistounknownRussia
- Tonto Teamnation-stateChina
- Tortoiseshellnation-stateIran
- LOTUS PANDAnation-stateChina
- Moleratsnation-statePalestine
- PLATINUMunknown
- APT18nation-stateChina
- Operation C-Majornation-statePakistan
- POLONIUMnation-stateLebanon
- El MacheteunknownUnknown
- Flying Kittennation-stateIran
- Cleavernation-stateIran
Most-used techniques25
The most commonly used TTPs include spearphishing (T1566.001, T1566.002), transferring malicious files (T1105, T1204.002), and after gaining access, data exfiltration (T1005, T1567.002) and discovery (T1016, T1518.001) techniques.
- T1566.001Spearphishing Attachment
- T1105Ingress Tool Transfer
- T1204.002Malicious File
- T1547.001Registry Run Keys / Startup Folder
- T1189Drive-by Compromise
- T1588.002Tool
- T1005Data from Local System
- T1566.002Spearphishing Link
- T1567.002Exfiltration to Cloud Storage
- T1016System Network Configuration Discovery
- T1021.001Remote Desktop Protocol
- T1053.005Scheduled Task
- T1056.001Keylogging
- T1059.001PowerShell
- T1059.003Windows Command Shell
- T1074.001Local Data Staging
- T1078Valid Accounts
- T1112Modify Registry
- T1518.001Security Software Discovery
- T1543.003Windows Service
- T1003.001LSASS Memory
- T1020Automated Exfiltration
- T1021.002SMB/Windows Admin Shares
- T1027.013Encrypted/Encoded File
- T1036.005Match Legitimate Resource Name or Location
Defense6
- 01
Enhancing email security and increasing defense against spearphishing attacks
- 02
Implementing EDR solutions to detect malicious activities in networks and systems
- 03
Increasing user security awareness and developing skills to recognize malicious emails
- 04
Regularly analyzing system and network configurations and eliminating security gaps
- 05
Implementing Multi-Factor Authentication (MFA) and strengthening valid account management
- 06
Regularly updating and patching applied software and systems
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources โ not a substitute for a tailored risk assessment.