Gorgon Group

APT / StateG0078
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)16
SourceMITRE ATT&CK
0
Also known as:ATK92G0078Pasty GeminiSubaat

Vexday analysis

Gorgon Group é um grupo de ameaça cujos membros são suspeitos de ter base no Paquistão ou conexões com o país. O grupo conduziu uma mistura de ataques criminosos e direcionados, incluindo campanhas contra organizações governamentais no Reino Unido, Espanha, Rússia e Estados Unidos. Catalogado no MITRE ATT&CK sob o identificador G0078, o grupo possui 16 técnicas documentadas na matriz.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity27
Impact: High
T1566.001T1059.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionPowerShellPERSPersistenceRegistry Run Keys/ Startup Folder

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 16

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 743

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port2.56.165.157:991NjRATthreatfox
ip:port103.83.87.87:26900Remcosthreatfox
ip:port103.83.87.87:27900Remcosthreatfox
ip:port103.83.87.87:22300Remcosthreatfox
ip:port103.83.87.87:24900Remcosthreatfox
domainwhichkindwahalabethisonesooluwahelurboi.duckdns.orgRemcosthreatfox
ip:port155.103.69.20:14647Remcosthreatfox
domaineventras.duckdns.orgRemcosthreatfox
ip:port107.175.88.92:2404Remcosthreatfox
ip:port87.120.244.219:13131Remcosthreatfox
ip:port77.110.108.14:9001Remcosthreatfox
ip:port80.97.160.237:23401Remcosthreatfox
ip:port91.193.7.162:13309Remcosthreatfox
ip:port45.74.3.160:2404Remcosthreatfox
ip:port185.91.126.112:443Remcosthreatfox
ip:port144.24.14.113:7005Remcosthreatfox
ip:port185.116.238.123:8088Remcosthreatfox
ip:port104.251.181.148:1427Remcosthreatfox
ip:port15.204.115.143:2404Remcosthreatfox
ip:port104.251.181.148:443Remcosthreatfox
ip:port104.251.181.148:80Remcosthreatfox
ip:port185.91.126.107:443Remcosthreatfox
domainxoso6640.comRemcosthreatfox
domainaseguradora2026.kozow.comRemcosthreatfox
domain2301amarilloa.kozow.comRemcosthreatfox
domainnordking.spaceRemcosthreatfox
domainnordkingbackup.spaceRemcosthreatfox
domaincreatifanay.duckdns.orgRemcosthreatfox
domaincrushanytics.duckdns.orgRemcosthreatfox
domainnordkingbackup1.spaceRemcosthreatfox

+743 indicators in total. See them all on the IOCs page.

Gorgon Group uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →