relayshieldadmin/mitre-attack-groups
RelayShield MITRE ATT&CK Group-Technique Mapping A structured slice of MITRE ATT&CK Enterprise data: 189 named threat actor groups, each mapped to its associated ATT&CK techniques and software, with descriptions and source citations. This is a cleaned, machine-readable export of MITRE's public STIX bundle — useful if you want group→technique mappings without parsing STIX yourself. Fields Field Type Description group_id string MITRE ATT&CK group ID (e.g.… See the full description on the dataset page: https://huggingface.co/datasets/relayshieldadmin/mitre-attack-groups.
029
1[2 {3 "group_id": "G0001",4 "name": "Axiom",5 "aliases": [6 "Axiom",7 "Group 72"8 ],9 "country_origin": "Unknown",10 "description": "[Axiom](https://attack.mitre.org/groups/G0001) is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overlap between [Axiom](https://attack.mitre.org/groups/G0001) and [Winnti Group](https://attack.mitre.org/groups/G0044) but the two groups appear to be distinct based on differences in reporting on TTPs and targeting.(Citation: Kaspersky Winnti April 2013)(Citati",11 "url": "https://attack.mitre.org/groups/G0001",12 "technique_ids": [13 "T1001.002",14 "T1003",15 "T1005",16 "T1021.001",17 "T1078",18 "T1189",19 "T1190",20 "T1203",21 "T1546.008",22 "T1553",23 "T1560",24 "T1563.002",25 "T1566",26 "T1583.002",27 "T1583.003",28 "T1584.005"29 ],30 "software_ids": [31 "S0009",32 "S0012",33 "S0013",34 "S0021",35 "S0032",36 "S0203",37 "S0412",38 "S0672"39 ],40 "technique_count": 1641 },42 {43 "group_id": "G0002",44 "name": "Moafee",45 "aliases": [46 "Moafee"47 ],48 "country_origin": "Unknown",49 "description": "[Moafee](https://attack.mitre.org/groups/G0002) is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group [DragonOK](https://attack.mitre.org/groups/G0017). (Citation: Haq 2014)",50 "url": "https://attack.mitre.org/groups/G0002",51 "technique_ids": [52 "T1027.001"53 ],54 "software_ids": [55 "S0012"56 ],57 "technique_count": 158 },59 {60 "group_id": "G0003",61 "name": "Cleaver",62 "aliases": [63 "Cleaver",64 "Threat Group 2889",65 "TG-2889"66 ],67 "country_origin": "Unknown",68 "description": "[Cleaver](https://attack.mitre.org/groups/G0003) is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. (Citation: Cylance Cleaver) Strong circumstantial evidence suggests Cleaver is linked to Threat Group 2889 (TG-2889). (Citation: Dell Threat Group 2889)",69 "url": "https://attack.mitre.org/groups/G0003",70 "technique_ids": [71 "T1003.001",72 "T1557.002",73 "T1585.001",74 "T1587.001",75 "T1588.002"76 ],77 "software_ids": [78 "S0002",79 "S0004",80 "S0029",81 "S0056"82 ],83 "technique_count": 584 },85 {86 "group_id": "G0004",87 "name": "Ke3chang",88 "aliases": [89 "Ke3chang",90 "APT15",91 "Mirage",92 "Vixen Panda",93 "GREF",94 "Playful Dragon",95 "RoyalAPT",96 "NICKEL",97 "Nylon Typhoon"98 ],99 "country_origin": "Unknown",100 "description": "[Ke3chang](https://attack.mitre.org/groups/G0004) is a threat group attributed to actors operating out of China. [Ke3chang](https://attack.mitre.org/groups/G0004) has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America since at least 2010.(Citation: Mandiant Operation Ke3chang November 2014)(Citation: NCC Group APT15 Alive and Strong)(Citation: APT15 Intezer June 2018)(Citation: Microsoft NICKEL December 2021)",101 "url": "https://attack.mitre.org/groups/G0004",102 "technique_ids": [103 "T1003.001",104 "T1003.002",105 "T1003.003",106 "T1003.004",107 "T1005",108 "T1007",109 "T1016",110 "T1018",111 "T1020",112 "T1021.002",113 "T1027",114 "T1033",115 "T1036.002",116 "T1036.005",117 "T1041",118 "T1049",119 "T1056.001",120 "T1057",121 "T1059",122 "T1059.003",123 "T1069.002",124 "T1071.001",125 "T1071.004",126 "T1078",127 "T1078.004",128 "T1082",129 "T1083",130 "T1087.001",131 "T1087.002",132 "T1105",133 "T1114.002",134 "T1119",135 "T1133",136 "T1140",137 "T1190",138 "T1213.002",139 "T1543.003",140 "T1547.001",141 "T1558.001",142 "T1560",143 "T1560.001",144 "T1569.002",145 "T1583.005",146 "T1587.001",147 "T1588.002",148 "T1614.001"149 ],150 "software_ids": [151 "S0002",152 "S0039",153 "S0057",154 "S0096",155 "S0097",156 "S0100",157 "S0104",158 "S0227",159 "S0280",160 "S0439",161 "S0691"162 ],163 "technique_count": 46164 },165 {166 "group_id": "G0005",167 "name": "APT12",168 "aliases": [169 "APT12",170 "IXESHE",171 "DynCalc",172 "Numbered Panda",173 "DNSCALC"174 ],175 "country_origin": "Unknown",176 "description": "[APT12](https://attack.mitre.org/groups/G0005) is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.(Citation: Meyers Numbered Panda)",177 "url": "https://attack.mitre.org/groups/G0005",178 "technique_ids": [179 "T1102.002",180 "T1203",181 "T1204.002",182 "T1566.001",183 "T1568.003"184 ],185 "software_ids": [186 "S0003",187 "S0015",188 "S0040"189 ],190 "technique_count": 5191 },192 {193 "group_id": "G0006",194 "name": "APT1",195 "aliases": [196 "APT1",197 "Comment Crew",198 "Comment Group",199 "Comment Panda"200 ],201 "country_origin": "China",202 "description": "[APT1](https://attack.mitre.org/groups/G0006) is a Chinese threat group that has been attributed to the 2nd Bureau of the People\u2019s Liberation Army (PLA) General Staff Department\u2019s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398. (Citation: Mandiant APT1)",203 "url": "https://attack.mitre.org/groups/G0006",204 "technique_ids": [205 "T1003.001",206 "T1005",207 "T1007",208 "T1016",209 "T1021.001",210 "T1036.005",211 "T1049",212 "T1057",213 "T1059.003",214 "T1087.001",215 "T1114.001",216 "T1114.002",217 "T1119",218 "T1135",219 "T1550.002",220 "T1560.001",221 "T1566.001",222 "T1566.002",223 "T1583.001",224 "T1584.001",225 "T1585.002",226 "T1588.001",227 "T1588.002"228 ],229 "software_ids": [230 "S0002",231 "S0006",232 "S0008",233 "S0012",234 "S0017",235 "S0025",236 "S0026",237 "S0029",238 "S0039",239 "S0057",240 "S0100",241 "S0109",242 "S0119",243 "S0121",244 "S0122",245 "S0123",246 "S0345"247 ],248 "technique_count": 23249 },250 {251 "group_id": "G0007",252 "name": "APT28",253 "aliases": [254 "APT28",255 "IRON TWILIGHT",256 "SNAKEMACKEREL",257 "Swallowtail",258 "Group 74",259 "Sednit",260 "Sofacy",261 "Pawn Storm",262 "Fancy Bear",263 "STRONTIUM",264 "Tsar Team",265 "Threat Group-4127",266 "TG-4127",267 "Forest Blizzard",268 "FROZENLAKE",269 "GruesomeLarch"270 ],271 "country_origin": "Russia",272 "description": "[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub August 2020)(Citation: Cybersecurity Advisory GRU Brute Force Campaign July 2021) This group has been active since at least 2004.(Citation: DOJ GRU Indictment Jul 2018)(Citation: Ars Technica GRU indictment Jul 2018)(Citation: Crowdstrike DNC June 2016)(Citat",273 "url": "https://attack.mitre.org/groups/G0007",274 "technique_ids": [275 "T1001.001",276 "T1003",277 "T1003.001",278 "T1003.003",279 "T1005",280 "T1014",281 "T1021.002",282 "T1025",283 "T1027.013",284 "T1030",285 "T1036",286 "T1036.005",287 "T1037.001",288 "T1039",289 "T1040",290 "T1048.002",291 "T1056.001",292 "T1057",293 "T1059.001",294 "T1059.003",295 "T1068",296 "T1070.004",297 "T1070.006",298 "T1071.001",299 "T1071.003",300 "T1074.001",301 "T1074.002",302 "T1078",303 "T1078.004",304 "T1083",305 "T1090.002",306 "T1090.003",307 "T1091",308 "T1092",309 "T1098.002",310 "T1102.002",311 "T1105",312 "T1110",313 "T1110.001",314 "T1110.003",315 "T1113",316 "T1114.002",317 "T1119",318 "T1120",319 "T1133",320 "T1134.001",321 "T1137.002",322 "T1140",323 "T1189",324 "T1190",325 "T1199",326 "T1203",327 "T1204.001",328 "T1204.002",329 "T1210",330 "T1211",331 "T1213",332 "T1213.002",333 "T1218.011",334 "T1221",335 "T1498",336 "T1505.003",337 "T1528",338 "T1542.003",339 "T1546.015",340 "T1547.001",341 "T1550.001",342 "T1550.002",343 "T1557.004",344 "T1559.002",345 "T1560",346 "T1560.001",347 "T1564.001",348 "T1564.003",349 "T1566.001",350 "T1567",351 "T1573.001",352 "T1583.001",353 "T1583.003",354 "T1583.006",355 "T1584.008",356 "T1586.002",357 "T1588.002",358 "T1588.007",359 "T1589.001",360 "T1591",361 "T1595.002",362 "T1596",363 "T1598",364 "T1598.003",365 "T1669",366 "T1684.001",367 "T1685.005"368 ],369 "software_ids": [370 "S0002",371 "S0023",372 "S0039",373 "S0044",374 "S0045",375 "S0117",376 "S0134",377 "S0135",378 "S0136",379 "S0137",380 "S0138",381 "S0160",382 "S0161",383 "S0162",384 "S0174",385 "S0183",386 "S0191",387 "S0193",388 "S0243",389 "S0250",390 "S0251",391 "S0351",392 "S0397",393 "S0410",394 "S0502",395 "S0645",396 "S1187",397 "S1205",398 "S9035"399 ],400 "technique_count": 93401 },402 {403 "group_id": "G0008",404 "name": "Carbanak",405 "aliases": [406 "Carbanak",407 "Anunak"408 ],409 "country_origin": "Russia / Eastern Europe",410 "description": "[Carbanak](https://attack.mitre.org/groups/G0008) is a cybercriminal group that has used [Carbanak](https://attack.mitre.org/software/S0030) malware to target financial institutions since at least 2013. [Carbanak](https://attack.mitre.org/groups/G0008) may be linked to groups tracked separately as [Cobalt Group](https://attack.mitre.org/groups/G0080) and [FIN7](https://attack.mitre.org/groups/G0046) that have also used [Carbanak](https://attack.mitre.org/software/S0030) malware.(Citation: Kasper",411 "url": "https://attack.mitre.org/groups/G0008",412 "technique_ids": [413 "T1036.004",414 "T1036.005",415 "T1078",416 "T1102.002",417 "T1218.011",418 "T1219",419 "T1543.003",420 "T1588.002",421 "T1686"422 ],423 "software_ids": [424 "S0002",425 "S0029",426 "S0030",427 "S0108"428 ],429 "technique_count": 9430 },431 {432 "group_id": "G0009",433 "name": "Deep Panda",434 "aliases": [435 "Deep Panda",436 "Shell Crew",437 "WebMasters",438 "KungFu Kittens",439 "PinkPanther",440 "Black Vine"441 ],442 "country_origin": "Unknown",443 "description": "[Deep Panda](https://attack.mitre.org/groups/G0009) is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. (Citation: Alperovitch 2014) The intrusion into healthcare company Anthem has been attributed to [Deep Panda](https://attack.mitre.org/groups/G0009). (Citation: ThreatConnect Anthem) This group is also known as Shell Crew, WebMasters, KungFu Kittens, and PinkPanther. (Citation: RSA Shell Crew) [Deep Panda](https",444 "url": "https://attack.mitre.org/groups/G0009",445 "technique_ids": [446 "T1018",447 "T1021.002",448 "T1027.005",449 "T1047",450 "T1057",451 "T1059.001",452 "T1218.010",453 "T1505.003",454 "T1546.008",455 "T1564.003"456 ],457 "software_ids": [458 "S0021",459 "S0039",460 "S0057",461 "S0074",462 "S0080",463 "S0097",464 "S0142"465 ],466 "technique_count": 10467 },468 {469 "group_id": "G0010",470 "name": "Turla",471 "aliases": [472 "Turla",473 "IRON HUNTER",474 "Group 88",475 "Waterbug",476 "WhiteBear",477 "Snake",478 "Krypton",479 "Venomous Bear",480 "Secret Blizzard",481 "BELUGASTURGEON"482 ],483 "country_origin": "Russia",484 "description": "[Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of industries including government, embassies, military, education, research and pharmaceutical companies. [Turla](https://attack.mitre.org/groups/G0010) is known for conducting watering hole and spearphishing campaigns, and leveraging in-house tools and malwa",485 "url": "https://attack.mitre.org/groups/G0010",486 "technique_ids": [487 "T1005",488 "T1007",489 "T1012",490 "T1016",491 "T1016.001",492 "T1018",493 "T1021.002",494 "T1025",495 "T1027.005",496 "T1027.010",497 "T1027.011",498 "T1036.005",499 "T1049",500 "T1055",501 "T1055.001",502 "T1057",503 "T1059.001",504 "T1059.003",505 "T1059.005",506 "T1059.006",507 "T1059.007",508 "T1068",509 "T1069.001",510 "T1069.002",511 "T1071.001",512 "T1071.003",513 "T1078.003",514 "T1082",515 "T1083",516 "T1087.001",517 "T1087.002",518 "T1090",519 "T1090.001",520 "T1102",521 "T1102.002",522 "T1105",523 "T1106",524 "T1110",525 "T1112",526 "T1120",527 "T1124",528 "T1134.002",529 "T1140",530 "T1189",531 "T1201",532 "T1204.001",533 "T1213.006",534 "T1518.001",535 "T1546.003",536 "T1546.013",537 "T1547.001",538 "T1547.004",539 "T1553.006",540 "T1555.004",541 "T1560.001",542 "T1564.012",543 "T1566.002",544 "T1567.002",545 "T1570",546 "T1583.006",547 "T1584.003",548 "T1584.004",549 "T1584.006",550 "T1587.001",551 "T1588.001",552 "T1588.002",553 "T1615",554 "T1685"555 ],556 "software_ids": [557 "S0002",558 "S0022",559 "S0029",560 "S0039",561 "S0057",562 "S0075",563 "S0091",564 "S0096",565 "S0099",566 "S0102",567 "S0104",568 "S0126",569 "S0160",570 "S0168",571 "S0256",572 "S0265",573 "S0335",574 "S0363",575 "S0393",576 "S0395",577 "S0537",578 "S0538",579 "S0581",580 "S0587",581 "S0590",582 "S0668",583 "S1075",584 "S1141",585 "S1142",586 "S1143"587 ],588 "technique_count": 68589 },590 {591 "group_id": "G0011",592 "name": "PittyTiger",593 "aliases": [594 "PittyTiger"595 ],596 "country_origin": "Unknown",597 "description": "[PittyTiger](https://attack.mitre.org/groups/G0011) is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.(Citation: Bizeul 2014)(Citation: Villeneuve 2014)",598 "url": "https://attack.mitre.org/groups/G0011",599 "technique_ids": [600 "T1078",601 "T1588.002"602 ],603 "software_ids": [604 "S0002",605 "S0008",606 "S0010",607 "S0012",608 "S0032"609 ],610 "technique_count": 2611 },612 {613 "group_id": "G0012",614 "name": "Darkhotel",615 "aliases": [616 "Darkhotel",617 "DUBNIUM",618 "Zigzag Hail"619 ],620 "country_origin": "Unknown",621 "description": "[Darkhotel](https://attack.mitre.org/groups/G0012) is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Internet networks against traveling executives and other select guests. [Darkhotel](https://attack.mitre.org/groups/G0012) has also conducted spearphishing campaigns and infected victims through peer-to-peer and file sharing networks.(Citation: Kaspersky Darkhot",622 "url": "https://attack.mitre.org/groups/G0012",623 "technique_ids": [624 "T1016",625 "T1027.013",626 "T1036.005",627 "T1056.001",628 "T1057",629 "T1059.003",630 "T1080",631 "T1082",632 "T1083",633 "T1091",634 "T1105",635 "T1124",636 "T1140",637 "T1189",638 "T1203",639 "T1204.002",640 "T1497",641 "T1497.001",642 "T1497.002",643 "T1518.001",644 "T1547.001",645 "T1553.002",646 "T1566.001",647 "T1573.001"648 ],649 "software_ids": [],650 "technique_count": 24651 },652 {653 "group_id": "G0013",654 "name": "APT30",655 "aliases": [656 "APT30"657 ],658 "country_origin": "China",659 "description": "[APT30](https://attack.mitre.org/groups/G0013) is a threat group suspected to be associated with the Chinese government. While [Naikon](https://attack.mitre.org/groups/G0019) shares some characteristics with [APT30](https://attack.mitre.org/groups/G0013), the two groups do not appear to be exact matches.(Citation: FireEye APT30)(Citation: Baumgartner Golovkin Naikon 2015)",660 "url": "https://attack.mitre.org/groups/G0013",661 "technique_ids": [662 "T1204.002",663 "T1566.001"664 ],665 "software_ids": [666 "S0028",667 "S0031",668 "S0034",669 "S0035",670 "S0036"671 ],672 "technique_count": 2673 },674 {675 "group_id": "G0014",676 "name": "Night Dragon",677 "aliases": [678 "Night Dragon"679 ],680 "country_origin": "Unknown",681 "description": "[Night Dragon](https://attack.mitre.org/groups/G0014) is a campaign name for activity involving a threat group that has conducted activity originating primarily in China. (Citation: McAfee Night Dragon)",682 "url": "https://attack.mitre.org/groups/G0014",683 "technique_ids": [],684 "software_ids": [],685 "technique_count": 0686 },687 {688 "group_id": "G0015",689 "name": "Taidoor",690 "aliases": [691 "Taidoor"692 ],693 "country_origin": "Unknown",694 "description": "[Taidoor](https://attack.mitre.org/groups/G0015) has been deprecated, as the only technique it was linked to was deprecated in ATT&CK v7.",695 "url": "https://attack.mitre.org/groups/G0015",696 "technique_ids": [],697 "software_ids": [],698 "technique_count": 0699 },700 {701 "group_id": "G0016",702 "name": "APT29",703 "aliases": [704 "APT29",705 "IRON RITUAL",706 "IRON HEMLOCK",707 "NobleBaron",708 "Dark Halo",709 "NOBELIUM",710 "UNC2452",711 "YTTRIUM",712 "The Dukes",713 "Cozy Bear",714 "CozyDuke",715 "SolarStorm",716 "Blue Kitsune",717 "UNC3524",718 "Midnight Blizzard"719 ],720 "country_origin": "Russia",721 "description": "[APT29](https://attack.mitre.org/groups/G0016) is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR).(Citation: White House Imposing Costs RU Gov April 2021)(Citation: UK Gov Malign RIS Activity April 2021) They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. [APT29](https://attack.mitre.org/groups/G0016) reportedly compromised the Democratic National Committee star",722 "url": "https://attack.mitre.org/groups/G0016",723 "technique_ids": [724 "T1003.002",725 "T1003.004",726 "T1005",727 "T1016.001",728 "T1021.007",729 "T1027.001",730 "T1027.002",731 "T1027.006",732 "T1036.005",733 "T1037",734 "T1037.004",735 "T1047",736 "T1053.005",737 "T1059.001",738 "T1059.006",739 "T1059.009",740 "T1068",741 "T1070.004",742 "T1070.006",743 "T1078",744 "T1078.003",745 "T1078.004",746 "T1087.004",747 "T1090.002",748 "T1090.003",749 "T1090.004",750 "T1098.002",751 "T1098.005",752 "T1105",753 "T1110.001",754 "T1110.003",755 "T1114.002",756 "T1133",757 "T1136.003",758 "T1190",759 "T1199",760 "T1203",761 "T1204.001",762 "T1204.002",763 "T1218.005",764 "T1505.003",765 "T1528",766 "T1546.003",767 "T1546.008",768 "T1547.001",769 "T1548.002",770 "T1550.003",771 "T1553.005",772 "T1556.007",773 "T1566.001",774 "T1566.002",775 "T1566.003",776 "T1568",777 "T1573",778 "T1583.006",779 "T1586.002",780 "T1586.003",781 "T1587.001",782 "T1587.003",783 "T1588.002",784 "T1595.002",785 "T1621",786 "T1649",787 "T1651",788 "T1665",789 "T1685.002"790 ],791 "software_ids": [792 "S0002",793 "S0029",794 "S0037",795 "S0039",796 "S0046",797 "S0048",798 "S0049",799 "S0050",800 "S0051",801 "S0052",802 "S0053",803 "S0054",804 "S0057",805 "S0096",806 "S0100",807 "S0139",808 "S0150",809 "S0154",810 "S0175",811 "S0183",812 "S0195",813 "S0357",814 "S0511",815 "S0512",816 "S0513",817 "S0514",818 "S0515",819 "S0516",820 "S0518",821 "S0521",822 "S0552",823 "S0559",824 "S0560",825 "S0562",826 "S0565",827 "S0588",828 "S0589",829 "S0597",830 "S0633",831 "S0634",832 "S0635",833 "S0636",834 "S0637",835 "S0661",836 "S0677",837 "S0682",838 "S0684",839 "S1084",840 "S1187"841 ],842 "technique_count": 66843 },844 {845 "group_id": "G0017",846 "name": "DragonOK",847 "aliases": [848 "DragonOK"849 ],850 "country_origin": "Unknown",851 "description": "[DragonOK](https://attack.mitre.org/groups/G0017) is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, [DragonOK](https://attack.mitre.org/groups/G0017) is thought to have a direct or indirect relationship with the threat group [Moafee](https://attack.mitre.org/groups/G0002). (Citation: Operation Quantum Entanglement) It is known to use a variety of malware, including Sysget/HelloBridge, PlugX, PoisonIvy, Former",852 "url": "https://attack.mitre.org/groups/G0017",853 "technique_ids": [],854 "software_ids": [855 "S0012",856 "S0013"857 ],858 "technique_count": 0859 },860 {861 "group_id": "G0018",862 "name": "admin@338",863 "aliases": [864 "admin@338"865 ],866 "country_origin": "Unknown",867 "description": "[admin@338](https://attack.mitre.org/groups/G0018) is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy, typically using publicly available RATs such as [PoisonIvy](https://attack.mitre.org/software/S0012), as well as some non-public backdoors. (Citation: FireEye admin@338)",868 "url": "https://attack.mitre.org/groups/G0018",869 "technique_ids": [870 "T1007",871 "T1016",872 "T1036.005",873 "T1049",874 "T1059.003",875 "T1069.001",876 "T1082",877 "T1083",878 "T1087.001",879 "T1203",880 "T1204.002",881 "T1566.001"882 ],883 "software_ids": [884 "S0012",885 "S0039",886 "S0042",887 "S0043",888 "S0096",889 "S0100",890 "S0104"891 ],892 "technique_count": 12893 },894 {895 "group_id": "G0019",896 "name": "Naikon",897 "aliases": [898 "Naikon"899 ],900 "country_origin": "Unknown",901 "description": "[Naikon](https://attack.mitre.org/groups/G0019) is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People\u2019s Liberation Army\u2019s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Unit Cover Designator 78020).(Citation: CameraShy) Active since at least 2010, [Naikon](https://attack.mitre.org/groups/G0019) has primarily conducted operations against government, military, and civil organizations in Southeast Asia, as well as against internat",902 "url": "https://attack.mitre.org/groups/G0019",903 "technique_ids": [904 "T1016",905 "T1018",906 "T1036.004",907 "T1036.005",908 "T1046",909 "T1047",910 "T1053.005",911 "T1078.002",912 "T1137.006",913 "T1204.002",914 "T1518.001",915 "T1547.001",916 "T1566.001",917 "T1574.001"918 ],919 "software_ids": [920 "S0029",921 "S0039",922 "S0055",923 "S0057",924 "S0058",925 "S0059",926 "S0060",927 "S0061",928 "S0095",929 "S0096",930 "S0097",931 "S0108",932 "S0456",933 "S0629",934 "S0630"935 ],936 "technique_count": 14937 },938 {939 "group_id": "G0020",940 "name": "Equation",941 "aliases": [942 "Equation"943 ],944 "country_origin": "Unknown",945 "description": "[Equation](https://attack.mitre.org/groups/G0020) is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk drives. (Citation: Kaspersky Equation QA)",946 "url": "https://attack.mitre.org/groups/G0020",947 "technique_ids": [948 "T1120",949 "T1480.001",950 "T1542.002",951 "T1564.005"952 ],953 "software_ids": [],954 "technique_count": 4955 },956 {957 "group_id": "G0021",958 "name": "Molerats",959 "aliases": [960 "Molerats",961 "Operation Molerats",962 "Gaza Cybergang"963 ],964 "country_origin": "Unknown",965 "description": "[Molerats](https://attack.mitre.org/groups/G0021) is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.(Citation: DustySky)(Citation: DustySky2)(Citation: Kaspersky MoleRATs April 2019)(Citation: Cybereason Molerats Dec 2020)",966 "url": "https://attack.mitre.org/groups/G0021",967 "technique_ids": [968 "T1027.015",969 "T1053.005",970 "T1057",971 "T1059.001",972 "T1059.005",973 "T1059.007",974 "T1105",975 "T1140",976 "T1204.001",977 "T1204.002",978 "T1218.007",979 "T1547.001",980 "T1553.002",981 "T1555.003",982 "T1566.001",983 "T1566.002"984 ],985 "software_ids": [986 "S0012",987 "S0062",988 "S0543",989 "S0546",990 "S0547",991 "S0553"992 ],993 "technique_count": 16994 },995 {996 "group_id": "G0022",997 "name": "APT3",998 "aliases": [999 "APT3",1000 "Gothic Panda",1001 "Pirpi",1002 "UPS Team",1003 "Buckeye",1004 "Threat Group-0110",1005 "TG-0110"1006 ],1007 "country_origin": "Unknown",1008 "description": "[APT3](https://attack.mitre.org/groups/G0022) is a China-based threat group that researchers have attributed to China's Ministry of State Security.(Citation: FireEye Clandestine Wolf)(Citation: Recorded Future APT3 May 2017) This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Clandestine Wolf, and Operation Double Tap.(Citation: FireEye Clandestine Wolf)(Citation: FireEye Operation Double Tap) As of June 2015, the group appears to have shifted from targeting",1009 "url": "https://attack.mitre.org/groups/G0022",1010 "technique_ids": [1011 "T1003.001",1012 "T1005",1013 "T1016",1014 "T1018",1015 "T1021.001",1016 "T1021.002",1017 "T1027",1018 "T1027.002",1019 "T1027.005",1020 "T1033",1021 "T1036.010",1022 "T1041",1023 "T1049",1024 "T1053.005",1025 "T1056.001",1026 "T1057",1027 "T1059.001",1028 "T1059.003",1029 "T1069",1030 "T1070.004",1031 "T1074.001",1032 "T1078.002",1033 "T1082",1034 "T1083",1035 "T1087.001",1036 "T1090.002",1037 "T1095",1038 "T1098.007",1039 "T1104",1040 "T1105",1041 "T1110.002",1042 "T1136.001",1043 "T1203",1044 "T1204.001",1045 "T1218.011",1046 "T1543.003",1047 "T1546.008",1048 "T1547.001",1049 "T1552.001",1050 "T1555.003",1051 "T1560.001",1052 "T1564.003",1053 "T1566.002",1054 "T1574.001"1055 ],1056 "software_ids": [1057 "S0013",1058 "S0063",1059 "S0111",1060 "S0165",1061 "S0166",1062 "S0349"1063 ],1064 "technique_count": 441065 },1066 {1067 "group_id": "G0023",1068 "name": "APT16",1069 "aliases": [1070 "APT16"1071 ],1072 "country_origin": "Unknown",1073 "description": "[APT16](https://attack.mitre.org/groups/G0023) is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations. (Citation: FireEye EPS Awakens Part 2)",1074 "url": "https://attack.mitre.org/groups/G0023",1075 "technique_ids": [1076 "T1584.004"1077 ],1078 "software_ids": [1079 "S0064"1080 ],1081 "technique_count": 11082 },1083 {1084 "group_id": "G0024",1085 "name": "Putter Panda",1086 "aliases": [1087 "Putter Panda",1088 "APT2",1089 "MSUpdater"1090 ],1091 "country_origin": "Unknown",1092 "description": "[Putter Panda](https://attack.mitre.org/groups/G0024) is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA\u2019s 3rd General Staff Department (GSD). (Citation: CrowdStrike Putter Panda)",1093 "url": "https://attack.mitre.org/groups/G0024",1094 "technique_ids": [1095 "T1027.013",1096 "T1055.001",1097 "T1547.001",1098 "T1685"1099 ],1100 "software_ids": [1101 "S0065",1102 "S0066",1103 "S0067",1104 "S0068"1105 ],1106 "technique_count": 41107 },1108 {1109 "group_id": "G0025",1110 "name": "APT17",1111 "aliases": [1112 "APT17",1113 "Deputy Dog"1114 ],1115 "country_origin": "Unknown",1116 "description": "[APT17](https://attack.mitre.org/groups/G0025) is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations. (Citation: FireEye APT17)",1117 "url": "https://attack.mitre.org/groups/G0025",1118 "technique_ids": [1119 "T1583.006",1120 "T1585"1121 ],1122 "software_ids": [1123 "S0069"1124 ],1125 "technique_count": 21126 },1127 {1128 "group_id": "G0026",1129 "name": "APT18",1130 "aliases": [1131 "APT18",1132 "TG-0416",1133 "Dynamite Panda",1134 "Threat Group-0416"1135 ],1136 "country_origin": "Unknown",1137 "description": "[APT18](https://attack.mitre.org/groups/G0026) is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical. (Citation: Dell Lateral Movement)",1138 "url": "https://attack.mitre.org/groups/G0026",1139 "technique_ids": [1140 "T1027.013",1141 "T1053.002",1142 "T1059.003",1143 "T1070.004",1144 "T1071.001",1145 "T1071.004",1146 "T1078",1147 "T1082",1148 "T1083",1149 "T1105",1150 "T1133",1151 "T1547.001"1152 ],1153 "software_ids": [1154 "S0032",1155 "S0070",1156 "S0071",1157 "S0106",1158 "S0124"1159 ],1160 "technique_count": 121161 },1162 {1163 "group_id": "G0027",1164 "name": "Threat Group-3390",1165 "aliases": [1166 "Threat Group-3390",1167 "Earth Smilodon",1168 "TG-3390",1169 "Emissary Panda",1170 "BRONZE UNION",1171 "APT27",1172 "Iron Tiger",1173 "LuckyMouse",1174 "Linen Typhoon"1175 ],1176 "country_origin": "Unknown",1177 "description": "[Threat Group-3390](https://attack.mitre.org/groups/G0027) is a Chinese threat group that has extensively used strategic Web compromises to target victims.(Citation: Dell TG-3390) The group has been active since at least 2010 and has targeted organizations in the aerospace, government, defense, technology, energy, manufacturing and gambling/betting sectors.(Citation: SecureWorks BRONZE UNION June 2017)(Citation: Securelist LuckyMouse June 2018)(Citation: Trend Micro DRBControl February 2020)",1178 "url": "https://attack.mitre.org/groups/G0027",1179 "technique_ids": [1180 "T1003.001",1181 "T1003.002",1182 "T1003.004",1183 "T1005",1184 "T1012",1185 "T1016",1186 "T1018",1187 "T1021.006",1188 "T1027.002",1189 "T1027.013",1190 "T1027.015",1191 "T1030",1192 "T1033",1193 "T1046",1194 "T1047",1195 "T1049",1196 "T1053.002",1197 "T1055.012",1198 "T1056.001",1199 "T1059.001",1200 "T1059.003",