Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Poseidon Group

🌐Poseidon Group

🌐 Poseidon Group is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: Unknown. We map 14 detection use cases to this actor across 8 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.

View full actor card → All threat actors MITRE ATT&CK group spec (G0033) ↗
14Use cases
0Articles
8Techniques
0IOCs

About this actor (MITRE)

[Poseidon Group](https://attack.mitre.org/groups/G0033) is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the [Poseidon Group](https://attack.mitre.org/groups/G0033) as a security firm. (Citation: Kaspersky Poseidon Group)

Known aliases

Poseidon Group

Top techniques

All other tracked techniques

Detection use cases (14)

Poseidon Group IGT-style net.exe reconnaissance burst (T1007/T1049/T1057/T1087) AI · profile S Poseidon Group masqueraded service binary spawning shell (T1036.005 + T1059.001) AI · profile SΣ Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) MITRE match LSASS process access / dump (credential theft) MITRE match Office app spawning script/LOLBin child process MITRE match Phishing-link click correlated to endpoint execution MITRE match PowerShell encoded / obfuscated command MITRE match AdsiSearcher Account Discovery MITRE match Attacker Tools On Endpoint MITRE match Detect AzureHound Command-Line Arguments MITRE match Detect AzureHound File Modifications MITRE match Detect Mimikatz With PowerShell Script Block Logging MITRE match