Financial Services sector
64 groups observed targeting this sector
Financial Services sector is primarily targeted by nation-state (APT42, OilRig, QUILTED TIGER, WIZARD SPIDER, etc.) and crime (incransom, play, anubis, etc.) actors.
Groups targeting you25
- APT42nation-stateIran
- Earth LuscaunknownChina
- incransomcrime
- LAPSUSunknown
- OilRignation-stateIran
- playcrime
- QUILTED TIGERnation-stateIndia
- TA505unknownRussia
- WIZARD SPIDERnation-stateRussia
- Storm-1567unknown
- APT19nation-stateChina
- APT-C-36unknown
- Tortoiseshellnation-stateIran
- Moleratsnation-statePalestine
- WOLF SPIDERunknownRO
- POLONIUMnation-stateLebanon
- APT41nation-stateChina
- TEMPER PANDAnation-stateChina
- GCMANunknownRussia
- ANTHROPOID SPIDERunknown
- AntlionunknownChina
- anubiscrime
- APT-C-12unknown
- AridVipernation-statePalestine
- auroracrime
Most-used techniques25
The most-used TTPs are spearphishing (T1566.001, T1566.002), malicious tool transfer (T1588.002, T1105), and legitimate resource masquerading (T1036.005) techniques. These techniques are used to gain initial access and discover internal systems.
- T1566.001Spearphishing Attachment
- T1588.002Tool
- T1036.005Match Legitimate Resource Name or Location
- T1059.005Visual Basic
- T1105Ingress Tool Transfer
- T1204.002Malicious File
- T1566.002Spearphishing Link
- T1016System Network Configuration Discovery
- T1021.001Remote Desktop Protocol
- T1059.001PowerShell
- T1059.003Windows Command Shell
- T1078Valid Accounts
- T1112Modify Registry
- T1133External Remote Services
- T1560.001Archive via Utility
- T1583.001Domains
- T1003.001LSASS Memory
- T1005Data from Local System
- T1018Remote System Discovery
- T1071.001Web Protocols
- T1083File and Directory Discovery
- T1090Proxy
- T1132.001Standard Encoding
- T1189Drive-by Compromise
- T1518.001Security Software Discovery
Defense5
- 01
Enhance email security and boost defenses against spearphishing attacks
- 02
Improve network and system monitoring and implement EDR solutions
- 03
Increase user security awareness and implement MFA
- 04
Ensure system and software updates and patch vulnerabilities
- 05
Use behavioral analysis to detect suspicious activities
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources โ not a substitute for a tailored risk assessment.