ATT&CKGroupsGorgon Group

Gorgon Group

G0078

Threat group.View on attack.mitre.org

About this group

Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States.

Techniques used16

Procedure examples16

TechniqueProcedure example
T1055.002
Portable Executable Injection

Gorgon Group malware can download a remote access tool, ShiftyBug, and inject into another process.

T1055.012
Process Hollowing

Gorgon Group malware can use process hollowing to inject one of its trojans into another process.

T1059.001
PowerShell

Gorgon Group malware can use PowerShell commands to download and execute a payload and open a decoy document on the victim’s machine.

T1059.003
Windows Command Shell

Gorgon Group malware can use cmd.exe to download and execute payloads and to execute commands on the system.

T1059.005
Visual Basic

Gorgon Group has used macros in Spearphishing Attachments as well as executed VBScripts on victim machines.

T1105
Ingress Tool Transfer

Gorgon Group malware can download additional files from C2 servers.

T1106
Native API

Gorgon Group malware can leverage the Windows API call, CreateProcessA(), for execution.

T1112
Modify Registry

Gorgon Group malware can deactivate security mechanisms in Microsoft Office by editing several keys and values under HKCU\Software\Microsoft\Office\.

T1140
Deobfuscate/Decode Files or Information

Gorgon Group malware can decode contents from a payload that was Base64 encoded and write the contents to a file.

T1204.002
Malicious File

Gorgon Group attempted to get users to launch malicious Microsoft Office attachments delivered via spearphishing emails.

T1547.001
Registry Run Keys / Startup Folder

Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence.

T1547.009
Shortcut Modification

Gorgon Group malware can create a .lnk file and add a Registry Run key to establish persistence.

T1564.003
Hidden Window

Gorgon Group has used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.

T1566.001
Spearphishing Attachment

Gorgon Group sent emails to victims with malicious Microsoft Office documents attached.

T1588.002
Tool

Gorgon Group has obtained and used tools such as QuasarRAT and Remcos.

View all 16 procedure examples

Software4

Campaigns0

None recorded.

References1

  1. Unit 42 Gorgon Group Aug 2018 Open source
    Falcone, R., et al. (2018, August 02). The Gorgon Group: Slithering Between Nation State and Cybercrime. Retrieved August 7, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.