Transportation Systems sector
47 groups observed targeting this sector
Transportation Systems are targeted by crime and nation-state actors, as well as unknown type actors.
Groups targeting you25
- incransomcrime
- Storm-1567unknown
- Tortoiseshellnation-stateIran
- POLONIUMnation-stateLebanon
- APT41nation-stateChina
- AiLockcrime
- APT14nation-stateChina
- APT73unknown
- arcusmediacrime
- AridVipernation-statePalestine
- auroracrime
- Blackatomnation-statePalestine
- blacknevascrime
- Chamelgangunknown
- chaoscrime
- clopcrime
- Cotton Sandstormnation-stateIran
- CRPxOcrime
- Curious GorgeunknownChina
- DAGGER PANDAnation-stateChina
- Dark Projectcrime
- Deadlockcrime
- embargocrime
- everestcrime
- ExfilSquadunknown
Most-used techniques25
Most-used TTPs include Valid Accounts (T1078), PowerShell (T1059.001), Remote Desktop Protocol (T1021.001), Exfiltration to Cloud Storage (T1567.002), and Tool usage (T1588.002). These techniques are primarily used for gaining access, stealing data, and hiding operations.
- T1021.001Remote Desktop Protocol
- T1036.005Match Legitimate Resource Name or Location
- T1059.001PowerShell
- T1078Valid Accounts
- T1567.002Exfiltration to Cloud Storage
- T1588.002Tool
- T1657Financial Theft
- T1685Disable or Modify Tools
- T1005Data from Local System
- T1014Rootkit
- T1018Remote System Discovery
- T1041Exfiltration Over C2 Channel
- T1046Network Service Discovery
- T1047Windows Management Instrumentation
- T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1057Process Discovery
- T1059.003Windows Command Shell
- T1071Application Layer Protocol
- T1074Data Staged
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1087.002Domain Account
- T1090Proxy
- T1102.002Bidirectional Communication
- T1105Ingress Tool Transfer
Defense5
- 01
Monitoring and managing Valid Accounts (T1078)
- 02
Restricting the use of PowerShell (T1059.001) and other scripting tools
- 03
Enhancing security measures for Remote Desktop Protocol (T1021.001)
- 04
Monitoring and managing access to Cloud Storage (T1567.002)
- 05
Implementing EDR solutions and detecting Tool usage (T1588.002)
Built from the threat archive: which groups target this sector and the MITRE ATT&CK techniques they use (MISP Galaxy, MITRE ATT&CK, ransomware.live). Guidance is general and grounded in the sources — not a substitute for a tailored risk assessment.