Government Facilities sector
147 groups observed targeting this sector
Government facilities are primarily targeted by nation-state actors (APT10, APT15, APT28, APT29, APT32, APT37, APT40, APT42, ENERGETIC BEAR, Kimsuky, Lazarus Group, LYCEUM, MuddyWater, OilRig, QUILTED TIGER, RAZOR TIGER, Sandworm, Tick, Turla) and actors with unknown motivations (APT27, Earth Lusca, Gamaredon Group, ShinyHunters, TA505). Crime actors (incransom) are also active in this sector.
Groups targeting you25
- APT10nation-stateChina
- APT15nation-stateChina
- APT27unknownChina
- APT28nation-stateRussia
- APT29nation-stateRussia
- APT32nation-stateVietnam
- APT37nation-stateNorth Korea
- APT40nation-stateChina
- APT42nation-stateIran
- Earth LuscaunknownChina
- ENERGETIC BEARnation-stateRussia
- Gamaredon GroupunknownRussia
- incransomcrime
- Kimsukynation-stateNorth Korea
- Lazarus Groupnation-stateNorth Korea
- LYCEUMnation-stateIran
- MuddyWaternation-stateIran
- OilRignation-stateIran
- QUILTED TIGERnation-stateIndia
- RAZOR TIGERnation-stateIndia
- Sandwormnation-stateRussia
- ShinyHuntersunknown
- TA505unknownRussia
- Ticknation-stateChina
- Turlanation-stateRussia
Most-used techniques25
The most used TTPs are spearphishing (T1566.001, T1566.002), malicious files (T1204.002), ingress tool transfer (T1105), and registry manipulation (T1547.001, T1112) techniques. These techniques are used to gain initial access, persist, and exfiltrate data.
- T1566.001Spearphishing Attachment
- T1204.002Malicious File
- T1105Ingress Tool Transfer
- T1547.001Registry Run Keys / Startup Folder
- T1588.002Tool
- T1036.005Match Legitimate Resource Name or Location
- T1005Data from Local System
- T1566.002Spearphishing Link
- T1003.001LSASS Memory
- T1021.001Remote Desktop Protocol
- T1027.013Encrypted/Encoded File
- T1083File and Directory Discovery
- T1059.003Windows Command Shell
- T1059.005Visual Basic
- T1189Drive-by Compromise
- T1567.002Exfiltration to Cloud Storage
- T1583.001Domains
- T1016System Network Configuration Discovery
- T1047Windows Management Instrumentation
- T1059.001PowerShell
- T1068Exploitation for Privilege Escalation
- T1074.001Local Data Staging
- T1082System Information Discovery
- T1112Modify Registry
- T1190Exploit Public-Facing Application
Defense5
- 01
Enhance email security and implement measures to defend against spearphishing attacks
- 02
Use EDR solutions for endpoint security and monitor registry changes
- 03
Increase user security awareness and implement MFA
- 04
Strengthen network security and implement measures to detect C2 traffic
- 05
Ensure the security of public-facing applications and implement measures to defend against T1190
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources โ not a substitute for a tailored risk assessment.