Also known as: G0033
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm. (Citation: Kaspersky Poseidon Group)
Executive Summary
The Poseidon Group, also known as G0033, is a Portuguese-speaking cyber threat group active since at least 2005. The group primarily engages in extortion through data exfiltration and blackmail, targeting various sectors to coerce victims into hiring them as security firms. Their activities demonstrate a blend of technical proficiency and strategic operational tactics, making them a persistent and impactful threat to organizations.
Goals & Targeting
The Poseidon Group's strategic objectives appear to center around financial gain through extortion and manipulation of victim organizations. Their targeting profile suggests a focus on sectors with high-value data, such as finance, healthcare, and technology. The group's operational strategy involves leveraging their own purported cybersecurity expertise to blackmail victims into contractual relationships. This approach likely enables them to operate under the radar while maximizing their financial gains. Their victims are typically organizations that value confidentiality and security but may lack sufficient defenses against sophisticated cyber threats.
Enhanced Description
The Poseidon Group is a cyber threat actor operating with a focus on extortion through data theft and blackmail. The group has been active since at least 2005, targeting various sectors and leveraging information exfiltrated from victim companies to coerce them into contractual arrangements as security providers. This unique operational model sets the group apart, as they capitalize on their own expertise in cybersecurity to manipulate victims. Their activities demonstrate a sophisticated understanding of both technical and organizational vulnerabilities. While specific details about their campaigns are limited, their use of known tactics such as credential dumping and PowerShell abuse suggests a proficiency in common cyberattack techniques. The Poseidon Group's targeting strategy appears to focus on sectors with high-value intellectual property or sensitive data, including financial services, healthcare, and technology industries. Despite their history, the group remains under-documented compared to other major threat actors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The Poseidon Group's campaigns are characterized by their focus on high-profile targets in critical sectors. Their operational tempo appears to be patient and deliberate, with a preference for maintaining persistence within victim networks to facilitate data exfiltration and extortion attempts. While specific campaign details remain scarce due to the group's under-documented nature, their activities indicate a long-term strategic approach. Notable past operations include incidents where they leveraged stolen data to blackmaik victims into contractual relationships, which likely provided them with both financial gain and operational cover.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the data regarding the Poseidon Group is moderate. While their general TTPs, such as credential dumping and PowerShell abuse, are well-documented through linked MITRE ATT&CK techniques, there is limited public information about specific campaigns, targets, or tools used by the group. The lack of detailed reporting on their activities makes it challenging to fully characterize their capabilities and operational scope. Additionally, the absence of publicly available sample IOCs limits the ability to define precise detection patterns.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
8
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
4
Tactics