Information Technology sector
84 groups observed targeting this sector
The Information Technology sector is targeted by nation-state (APT17, APT19, Tortoiseshell, APT18, POLONIUM, APT41, Cleaver, AridViper, BANISHED KITTEN) and crime (incransom, play, AiLock, anubis, arcusmedia, AuditTeam, aurora, Barracuda, blacknevas) actors.
Groups targeting you25
- APT27unknownChina
- APT5unknownChina
- incransomcrime
- LAPSUSunknown
- LYCEUMnation-stateIran
- playcrime
- ShinyHuntersunknown
- Storm-1567unknown
- APT17nation-stateChina
- APT19nation-stateChina
- Tortoiseshellnation-stateIran
- APT18nation-stateChina
- POLONIUMnation-stateLebanon
- APT41nation-stateChina
- Cleavernation-stateIran
- AiLockcrime
- anubiscrime
- APT73unknown
- arcusmediacrime
- AridVipernation-statePalestine
- AuditTeamcrime
- auroracrime
- BANISHED KITTENnation-stateIran
- Barracudacrime
- blacknevascrime
Most-used techniques25
The most-used TTPs include Valid Accounts (T1078), Tool (T1588.002), Remote Desktop Protocol (T1021.001), Ingress Tool Transfer (T1105), Exploit Public-Facing Application (T1190), and External Remote Services (T1133). These techniques are primarily used for initial access, data exfiltration, and system discovery.
- T1078Valid Accounts
- T1588.002Tool
- T1021.001Remote Desktop Protocol
- T1105Ingress Tool Transfer
- T1190Exploit Public-Facing Application
- T1003.001LSASS Memory
- T1059.001PowerShell
- T1082System Information Discovery
- T1133External Remote Services
- T1567.002Exfiltration to Cloud Storage
- T1005Data from Local System
- T1016System Network Configuration Discovery
- T1059.003Windows Command Shell
- T1189Drive-by Compromise
- T1657Financial Theft
- T1685Disable or Modify Tools
- T1018Remote System Discovery
- T1027.010Command Obfuscation
- T1030Data Transfer Size Limits
- T1036.005Match Legitimate Resource Name or Location
- T1046Network Service Discovery
- T1053.002At
- T1056.001Keylogging
- T1057Process Discovery
- T1068Exploitation for Privilege Escalation
Defense5
- 01
Enhance the security of initial access points (especially public-facing applications)
- 02
Monitor and manage Valid Accounts
- 03
Secure remote work protocols (Remote Desktop Protocol, External Remote Services)
- 04
Implement controls for data exfiltration (Exfiltration to Cloud Storage) and data collection from local systems (Data from Local System)
- 05
Deploy security tools (EDR, MFA) and update existing security policies
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources โ not a substitute for a tailored risk assessment.