Poseidon Group

MITRE ATT&CK: G0033 View on attack.mitre.org

Aliases: Poseidon Group

First seen
2005-01-01 00:00:00
Origin
BR
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:31:22

Targeted industries: financial-services professional-services technology-and-telecommunications

Targeted regions: country_code:br country_code:us

Context

Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm.

Detection coverage

  • 279 Sigma rules

Malware & tools used

  • System Network Connections Discovery (attack-pattern)
  • OS Credential Dumping (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Domain Account (attack-pattern)
  • Local Account (attack-pattern)
  • Process Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • PowerShell (attack-pattern)

Reports & references

  • MITRE ATT&CK — Groups (report)
  • Kaspersky — 73673 (report)
  • MITRE ATT&CK — G0033 (report)

External references