Poseidon Group

Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into contracting the Poseidon Group as a security firm. [1]

ID: G0033
Version: 1.0

Techniques Used

EnterpriseT1087Account DiscoveryPoseidon Group searches for administrator accounts on both the local victim machine and the network.[1]
EnterpriseT1003Credential DumpingPoseidon Group conducts credential dumping on victims, with a focus on obtaining credentials belonging to domain and database servers.[1]
EnterpriseT1036MasqueradingPoseidon Group tools attempt to spoof anti-virus processes as a means of self-defense.[1]
EnterpriseT1086PowerShellThe Poseidon Group's Information Gathering Tool (IGT) includes PowerShell components.[1]
EnterpriseT1057Process DiscoveryAfter compromising a victim, Poseidon Group lists all running processes.[1]
EnterpriseT1049System Network Connections DiscoveryPoseidon Group obtains and saves information about victim network interfaces and addresses.[1]
EnterpriseT1007System Service DiscoveryAfter compromising a victim, Poseidon Group discovers all running services.[1]