Gorgon Group
MITRE ATT&CK: G0078 View on attack.mitre.org
Aliases: Gorgon Group, Subaat, ATK92, Pasty Gemini
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 11:55:00
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:gb country_code:es country_code:ru country_code:us
Context
Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States.
Detection coverage
- 17 YARA rules
- 659 Sigma rules
Malware & tools used
- Process Hollowing (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Native API (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- PowerShell (attack-pattern)
- Windows Command Shell (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Hidden Window (attack-pattern)
- Portable Executable Injection (attack-pattern)
- Modify Registry (attack-pattern)
- Shortcut Modification (attack-pattern)
- Malicious File (attack-pattern)
- Tool (attack-pattern)
- Visual Basic (attack-pattern)
- Remcos (malware)
- NanoCore (malware)
- njRAT (malware)
- QuasarRAT (malware)
Reports & references
- Palo Alto Unit 42 — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)
- Palo Alto Unit 42 — Unit42 Tracking Subaat Targeted Phishing Attacks Point Leader Threat Actors Repository (report)
- Palo Alto Unit 42 — Aggah Campaign Bit Ly Blogspot And Pastebin Used For C2 In Large Scale Campaign (report)
- MITRE ATT&CK — G0078 (report)
- Palo Alto Unit 42 — Pastygemini (report)
- researchcenter.paloaltonetworks.com — Unit42 Gorgon Group Slithering Nation State Cybercrime (report)