Gorgon Group malware can download a remote access tool, ShiftyBug, and inject into another process.2
group
Gorgon Group G0078
- Created
- 17 October 2018
- Last modified
- 31 July 2026
- Alias
- Gorgon Group
Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, including campaigns against government organizations in the United Kingdom, Spain, Russia, and the United States. [1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0078
Gorgon Group malware can use process hollowing to inject one of its trojans into another process.3
Gorgon Group malware can use PowerShell commands to download and execute a payload and open a decoy document on the victim’s machine.4
Gorgon Group malware can use cmd.exe to download and execute payloads and to execute commands on the system.5
Gorgon Group has used macros in Spearphishing Attachments as well as executed VBScripts on victim machines.6
Gorgon Group malware can download additional files from C2 servers.7
Standing G0078
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
48th percentile · 52% of 176 ATT&CK groups have more Enterprise techniques.
48th percentile · 52% of 176 ATT&CK groups have more tactics spanned.
55th percentile · 55% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
89th percentile · 89% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0078
1125 distinct rules cover the 16 techniques recorded for this group. The 1227 technique-to-rule mappings resolve to 1125 distinct rules, because one rule can cover several techniques. 744 Sigma · 381 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org