Also known as: Subaat, Gorgon Group, ATK92, G0078, Pasty Gemini
Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States. (Citation: Unit 42 Gorgon Group Aug 2018)
Executive Summary
The Gorgon Group, also known as Subaat, ATK92, G0078, and Pasty Gemini, is a threat actor suspected to have members with ties to Pakistan. The group conducts espionage and criminal attacks targeting government organizations in the UK, Spain, Russia, and the US. Their activities include the use of malware like NanoCore and njRAT, as well as various MITRE ATT&CK techniques such as T1566.001 (Spearphishing Attachment) and T1204.002 (Malicious File). The Gorgon Group poses a significant threat to government and critical infrastructure sectors due to their blending of criminal activity with targeted espionage.
Goals & Targeting
The Gorgon Group appears to have dual motivations: espionage for strategic or political purposes and criminal activities likely aimed at financial gain. Their targeting of government organizations suggests a focus on accessing sensitive information, while their geographic diversity indicates an ability to operate across borders. The group's members are suspected to be based in Pakistan or connected to it, which may influence their targeting priorities.
Enhanced Description
The Gorgon Group is a cyber threat actor known for its diverse attack campaigns, ranging from espionage to criminal activities. The group has demonstrated the ability to target multiple countries, including the UK, Spain, Russia, and the US, focusing primarily on government organizations. Their operations involve the use of sophisticated malware, such as NanoCore and njRAT, which are characterized by persistence, lateral movement, and information exfiltration capabilities. The Gorgon Group's tactics include malicious file deployments, registry modifications, and process hollowing, among others. These activities highlight a high level of operational sophistication, with a clear focus on intelligence gathering and potentially financial gain.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Gorgon Group has conducted campaigns targeting government organizations, leveraging sophisticated malware and persistence techniques. Their use of NanoCore and njRAT indicates a focus on long-term access and data exfiltration. Campaign patterns suggest operational continuity over several years, with attacks observed in multiple countries. Specific details about their campaign operations are limited but indicate a methodical approach to target selection and attack execution.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence exists in the Gorgon Group's profile, primarily due to linked intelligence and observed TTPs. However, specific details about their exact targeting criteria beyond governments remain unclear, as well as the full extent of their attack techniques and tools.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
16
Techniques
5
Tools
0
Campaigns
0
IOCs
0
Observed Data
7
Tactics