TERBIUM

First seen
2012-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:34:30

Targeted industries: energy-and-utilities

Context

Microsoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to organizations in the energy sector. Microsoft Threat Intelligence refers to the activity group behind these attacks as TERBIUM, following our internal practice of assigning rogue actors chemical element names.

Reports & references

  • Microsoft — Windows 10 Protection Detection And Response Against Recent Attacks (report)

External references