Threat group.View on attack.mitre.org
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm.
| Technique | Procedure example |
|---|---|
| T1003 OS Credential Dumping |
Poseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers. |
| T1007 System Service Discovery |
After compromising a victim, Poseidon Group discovers all running services. |
| T1036.005 Match Legitimate Resource Name or Location |
Poseidon Group tools attempt to spoof anti-virus processes as a means of self-defense. |
| T1049 System Network Connections Discovery |
Poseidon Group obtains and saves information about victim network interfaces and addresses. |
| T1057 Process Discovery |
After compromising a victim, Poseidon Group lists all running processes. |
| T1059.001 PowerShell |
The Poseidon Group's Information Gathering Tool (IGT) includes PowerShell components. |
| T1087.001 Local Account |
Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
| T1087.002 Domain Account |
Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.