Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Poseidon Group

Also known as: G0033

Description

Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm. (Citation: Kaspersky Poseidon Group)

AI Analysis

· 1 week ago

Executive Summary

The Poseidon Group, also known as G0033, is a Portuguese-speaking cyber threat group active since at least 2005. The group primarily engages in extortion through data exfiltration and blackmail, targeting various sectors to coerce victims into hiring them as security firms. Their activities demonstrate a blend of technical proficiency and strategic operational tactics, making them a persistent and impactful threat to organizations.

Goals & Targeting

The Poseidon Group's strategic objectives appear to center around financial gain through extortion and manipulation of victim organizations. Their targeting profile suggests a focus on sectors with high-value data, such as finance, healthcare, and technology. The group's operational strategy involves leveraging their own purported cybersecurity expertise to blackmail victims into contractual relationships. This approach likely enables them to operate under the radar while maximizing their financial gains. Their victims are typically organizations that value confidentiality and security but may lack sufficient defenses against sophisticated cyber threats.

Enhanced Description

The Poseidon Group is a cyber threat actor operating with a focus on extortion through data theft and blackmail. The group has been active since at least 2005, targeting various sectors and leveraging information exfiltrated from victim companies to coerce them into contractual arrangements as security providers. This unique operational model sets the group apart, as they capitalize on their own expertise in cybersecurity to manipulate victims. Their activities demonstrate a sophisticated understanding of both technical and organizational vulnerabilities. While specific details about their campaigns are limited, their use of known tactics such as credential dumping and PowerShell abuse suggests a proficiency in common cyberattack techniques. The Poseidon Group's targeting strategy appears to focus on sectors with high-value intellectual property or sensitive data, including financial services, healthcare, and technology industries. Despite their history, the group remains under-documented compared to other major threat actors.

Key Capabilities

  • Credential dumping via OS credential dumping
  • Use of PowerShell for malicious activities
  • Domain account access techniques
  • System service discovery
  • Network connection discovery
  • Process discovery

MITRE ATT&CK Tactics

Credential Access
Discovery
Lateral Movement
Defense Evasion
Collection
Exfiltration
Impact

ATT&CK Techniques

T1087.002
T1003
T1036.005
T1007
T1049
T1059.001
T1087.001
T1057

Software / Tooling

Custom tools for credential dumping and exfiltration
PowerShell-based scripts
Spear-phishing tools

Campaigns & Victims

The Poseidon Group's campaigns are characterized by their focus on high-profile targets in critical sectors. Their operational tempo appears to be patient and deliberate, with a preference for maintaining persistence within victim networks to facilitate data exfiltration and extortion attempts. While specific campaign details remain scarce due to the group's under-documented nature, their activities indicate a long-term strategic approach. Notable past operations include incidents where they leveraged stolen data to blackmaik victims into contractual relationships, which likely provided them with both financial gain and operational cover.

IOC Patterns

  • Use of domain account access techniques
  • Spear-phishing attempts targeting sensitive sectors
  • Excessive network connection discovery activities
  • OS credential dumping activities
  • PowerShell-based fileless malware

Recommended Actions

  • Implement strong credential management practices and regular audits
  • Monitor for unusual system service and network activity
  • Use endpoint detection and response (EDR) tools to detect PowerShell abuse
  • Conduct regular security awareness training to mitigate phishing attempts
  • Enhance network visibility and implement anomaly detection solutions

Suggested Tags

APT
cybercrime
extortion
data theft
financial sector
healthcare sector
technology sector

Confidence Assessment

The confidence in the data regarding the Poseidon Group is moderate. While their general TTPs, such as credential dumping and PowerShell abuse, are well-documented through linked MITRE ATT&CK techniques, there is limited public information about specific campaigns, targets, or tools used by the group. The lack of detailed reporting on their activities makes it challenging to fully characterize their capabilities and operational scope. Additionally, the absence of publicly available sample IOCs limits the ability to define precise detection patterns.

ATT&CK Techniques

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Kaspersky Poseidon Group — Kaspersky Lab's Global Research and Analysis Team. (2016, February 9). Poseidon Group: a Targeted Attack Boutique specializing in global cyber-espionage. Retrieved March 16, 2016.

Intel Summary

8

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

4

Tactics

Tags

APT
cybercrime
extortion
data theft
financial sector
healthcare sector
technology sector

Details

MITRE ID
G0033
Type
Unknown
Country of Origin
B
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--7ecc3b4f-5cdb-457e-b55a-df376b359446
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.