Energy sector
55 groups observed targeting this sector
The energy sector is targeted by nation-state actors (APT42, ENERGETIC BEAR, Kimsuky, LYCEUM, OilRig, Sandworm, Turla, Tortoiseshell, Molerats, APT41, Flying Kitten, Cleaver, AridViper) and crime actors (incransom, play, blackwater, BrainCipher, bravox, clop).
Groups targeting you25
- APT42nation-stateIran
- ENERGETIC BEARnation-stateRussia
- incransomcrime
- Kimsukynation-stateNorth Korea
- LYCEUMnation-stateIran
- OilRignation-stateIran
- playcrime
- Sandwormnation-stateRussia
- ShinyHuntersunknown
- Turlanation-stateRussia
- Storm-1567unknown
- APT-C-36unknown
- Tortoiseshellnation-stateIran
- Moleratsnation-statePalestine
- RASPITEunknown
- APT41nation-stateChina
- Flying Kittennation-stateIran
- Cleavernation-stateIran
- AridVipernation-statePalestine
- blackwatercrime
- BrainCiphercrime
- bravoxcrime
- BRONZE SPRINGunknownChina
- Chamelgangunknown
- clopcrime
Most-used techniques25
The most-used TTPs include Ingress Tool Transfer (T1105), Remote Desktop Protocol (T1021.001), Malicious File (T1204.002), Tool (T1588.002), and Spearphishing (T1566.001, T1566.002). These techniques are used for initial access, internal discovery, and data exfiltration.
- T1105Ingress Tool Transfer
- T1021.001Remote Desktop Protocol
- T1204.002Malicious File
- T1588.002Tool
- T1003.001LSASS Memory
- T1005Data from Local System
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1027.010Command Obfuscation
- T1059.001PowerShell
- T1082System Information Discovery
- T1133External Remote Services
- T1190Exploit Public-Facing Application
- T1566.001Spearphishing Attachment
- T1566.002Spearphishing Link
- T1583.001Domains
- T1587.001Malware
- T1685Disable or Modify Tools
- T1021.002SMB/Windows Admin Shares
- T1036.005Match Legitimate Resource Name or Location
- T1046Network Service Discovery
- T1059.003Windows Command Shell
- T1059.007JavaScript
- T1078Valid Accounts
- T1189Drive-by Compromise
Defense6
- 01
Harden initial access points (phishing, exploit)
- 02
Secure remote access protocols (RDP, VPN)
- 03
Monitor network activity and detect anomalous behavior
- 04
Keep applications and systems up-to-date and patched
- 05
Implement multi-factor authentication (MFA)
- 06
Use EDR solutions
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources โ not a substitute for a tailored risk assessment.