Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Gorgon Group

Also known as: Subaat, Gorgon Group, ATK92, G0078, Pasty Gemini

Description

Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States. (Citation: Unit 42 Gorgon Group Aug 2018)

AI Analysis

· 1 week ago

Executive Summary

The Gorgon Group, also known as Subaat, ATK92, G0078, and Pasty Gemini, is a threat actor suspected to have members with ties to Pakistan. The group conducts espionage and criminal attacks targeting government organizations in the UK, Spain, Russia, and the US. Their activities include the use of malware like NanoCore and njRAT, as well as various MITRE ATT&CK techniques such as T1566.001 (Spearphishing Attachment) and T1204.002 (Malicious File). The Gorgon Group poses a significant threat to government and critical infrastructure sectors due to their blending of criminal activity with targeted espionage.

Goals & Targeting

The Gorgon Group appears to have dual motivations: espionage for strategic or political purposes and criminal activities likely aimed at financial gain. Their targeting of government organizations suggests a focus on accessing sensitive information, while their geographic diversity indicates an ability to operate across borders. The group's members are suspected to be based in Pakistan or connected to it, which may influence their targeting priorities.

Enhanced Description

The Gorgon Group is a cyber threat actor known for its diverse attack campaigns, ranging from espionage to criminal activities. The group has demonstrated the ability to target multiple countries, including the UK, Spain, Russia, and the US, focusing primarily on government organizations. Their operations involve the use of sophisticated malware, such as NanoCore and njRAT, which are characterized by persistence, lateral movement, and information exfiltration capabilities. The Gorgon Group's tactics include malicious file deployments, registry modifications, and process hollowing, among others. These activities highlight a high level of operational sophistication, with a clear focus on intelligence gathering and potentially financial gain.

Key Capabilities

  • Spearphishing campaigns
  • Use of malware (NanoCore, njRAT)
  • Registry modifications
  • Malicious file deployment
  • Process hollowing

MITRE ATT&CK Tactics

Collection
Exfiltration
Lateral Movement
Defense-Evasion
Credential Access
Discovery

ATT&CK Techniques

T1204.002
T1112
T1055.002
T1059.001
T1588.002
T1055.012
T1547.009
T1547.001
T1685
T1564.003
T1059.005
T1105

Software / Tooling

NanoCore
njRAT

Campaigns & Victims

The Gorgon Group has conducted campaigns targeting government organizations, leveraging sophisticated malware and persistence techniques. Their use of NanoCore and njRAT indicates a focus on long-term access and data exfiltration. Campaign patterns suggest operational continuity over several years, with attacks observed in multiple countries. Specific details about their campaign operations are limited but indicate a methodical approach to target selection and attack execution.

IOC Patterns

  • Spearphishing with malicious attachments
  • Registry modifications for persistence
  • Use of njRAT malware
  • Process hollowing techniques

Recommended Actions

  • Implement advanced endpoint detection and response (EDR) solutions to detect malicious file activities.
  • Monitor for unusual registry changes indicative of persistence mechanisms.
  • Conduct regular phishing simulations to improve employee awareness of spearphishing attacks.
  • Apply patches and updates to mitigate vulnerabilities exploited by the group's tools.

Suggested Tags

APT
espionage
government
malware

Confidence Assessment

Moderate confidence exists in the Gorgon Group's profile, primarily due to linked intelligence and observed TTPs. However, specific details about their exact targeting criteria beyond governments remain unclear, as well as the full extent of their attack techniques and tools.

ATT&CK Techniques

Execution
5 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Unit 42 Gorgon Group Aug 2018 — Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

Intel Summary

16

Techniques

5

Tools

0

Campaigns

0

IOCs

0

Observed Data

7

Tactics

Tags

APT
Government Targeting
espionage
government
malware

Details

MITRE ID
G0078
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--1f21da59-6a13-455b-afd0-d58d0a5a7d27
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.