Gorgon Group

APT / StateG0078 ↗
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)16
SourceMITRE ATT&CK
0
Also known as:ATK92G0078Pasty GeminiSubaat

About the group

Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity27
Impact: High
T1566.001T1059.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionPowerShellPERSPersistenceRegistry Run Keys/ Startup Folder

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 16

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 1925

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port45.128.234.124:7070Remcosthreatfox
ip:port95.211.44.207:2404Remcosthreatfox
ip:port45.136.5.227:10123Remcosthreatfox
ip:port103.83.87.47:3838Remcosthreatfox
ip:port155.103.69.244:2929Remcosthreatfox
ip:port62.212.79.67:2404Remcosthreatfox
ip:port46.246.12.18:5987Remcosthreatfox
ip:port45.128.234.124:443Remcosthreatfox
ip:port198.135.49.110:4489Remcosthreatfox
ip:port37.120.206.165:60507Remcosthreatfox
ip:port103.83.87.86:2404Remcosthreatfox
ip:port185.149.24.115:2404Remcosthreatfox
ip:port128.90.108.225:2424Remcosthreatfox
ip:port103.83.86.40:14642Remcosthreatfox
ip:port31.59.137.81:4565Remcosthreatfox
domainjustily.duckdns.orgRemcosthreatfox
ip:port192.162.199.218:2222Quasar RATthreatfox
ip:port128.90.108.89:2424Remcosthreatfox
ip:port103.254.61.170:3889Remcosthreatfox
ip:port46.246.14.21:5987Remcosthreatfox
ip:port194.116.236.83:15800Remcosthreatfox
sha256_hashd7fea5f6217db6e04f75333a65a46cdfcc523c7f3ddc29cfaecb18cd8876ea98NjRATthreatfox
md5_hash1cf8cce965f8f2089ce67ef811b29d13NjRATthreatfox
sha1_hashca868ac1e4f42282fb74865fc2f9edf38b052e4bNjRATthreatfox
sha256_hashd5c4983535d57d69fc6f8c09ff4a3838d6a61ac6b149de67b89c0c062968d9cdNjRATthreatfox
sha1_hash19dc42491a499830d7638933b5f457740ffce395NjRATthreatfox
md5_hash1742ad51f743c9e518abec7fc6f9451bNjRATthreatfox
ip:port204.44.93.119:7878Remcosthreatfox
ip:port114.66.20.236:8008Quasar RATthreatfox
ip:port128.90.108.50:2424Remcosthreatfox

+1925 indicators in total. See them all on the IOCs page.

Gorgon Group uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →