Social-Engineering Intrusion Sets
Some intrusion sets are defined by what they exploit. These are defined by whom they talk to.
Of the threat actors we hold any ATT&CK mapping for, only seven carry a technique whose subject is a human being rather than a system — MFA request generation, spearphishing by voice, or malicious copy-and-paste. Those seven sit across three actor types and five origins, which means the site's own filters actively take this set apart: /threat-actors can sort by type, by threat level and by whether a group is popular or new, and none of those controls can express "talks its way in".
The roster below is not those seven. It is wider, because the mapping lags the reporting, and it is also narrower: two of the seven are absent, and so is the only one of them we classify as a hacktivist — which is why the groups listed here span two actor types rather than three.
State the denominator with the finding: fewer than a third of the groups we track carry any ATT&CK mapping at all, so a group's absence from this list is a statement about our coverage and not about its tradecraft. The page leads with the techniques and tooling these groups share, because that comparison is the thing a single-axis page cannot produce, and it moves as the mapping improves.
- Curated entries: 20
- Incidents attributed in the last 90 days: 60
- 32 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Acquire Infrastructure: Domains (T1583.001) 4/5 here · 44/171 tracked
- Obtain Capabilities: Tool (T1588.002) 5/5 here · 79/171 tracked
- Remote Access Tools: Remote Desktop Software (T1219.002) 3/5 here · 11/171 tracked
- Phishing: Spearphishing via Service (T1566.003) 3/5 here · 14/171 tracked
- Social Engineering: Impersonation (T1684.001) 3/5 here · 15/171 tracked
- Data Encrypted for Impact (T1486) 3/5 here · 19/171 tracked
- Remote Services: SSH (T1021.004) 3/5 here · 19/171 tracked
- Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001) 4/5 here · 55/171 tracked
- Develop Capabilities: Malware (T1587.001) 3/5 here · 24/171 tracked
- Exfiltration Over Web Service: Exfiltration to Cloud Storage (T1567.002) 3/5 here · 24/171 tracked
Shared tooling
- Cobalt Strike 3/5 here · 29/157 tracked
- Tor 2/5 here · 6/157 tracked
- AdFind 2/5 here · 12/157 tracked
- Impacket 2/5 here · 18/157 tracked
- Mimikatz 3/5 here · 51/157 tracked
- PsExec 2/5 here · 38/157 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Peak weeks
The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.
- ShinyHunters 42 of 139 claims in the week of 2025-09-29 · 30.2% of lifetime output · peaked in its DEBUT week
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Scattered Spider 1 incident — Ransomware · Unknown — 2023-09-11 — Help-desk impersonation and SIM swap; the reference implementation.
- Storm-1811 0 incidents — Ransomware · Unknown — Teams vishing into remote-access tooling.
- ShinyHunters 139 incidents — Ransomware · Unknown — 2026-08-02 — Credential-led data extortion at scale.
- Silent Ransom Group 30 incidents — Ransomware · Unknown — 2026-08-07 — Callback phishing.
- Black Basta 194 incidents — Ransomware · Russia — 2025-01-11 — Teams-based help-desk impersonation. Dormant in our log since January 2025.
- 3AM 25 incidents — Ransomware · Unknown — 2026-08-06 — Vishing-led intrusions; the tradecraft here is asserted in prose, not mapped.
- FIN7 0 incidents — Ransomware · Russia — Long-running social-engineering and lure development.
- Contagious Interview 0 incidents — APT · North Korea — A fake job interview is social engineering with a DPRK revenue motive.
- Famous Chollima 0 incidents — APT · North Korea — Fraudulent employment as an access technique.
- Jasper Sleet 0 incidents — APT · North Korea — Same tradecraft, separate designation.
- APT29 0 incidents — APT · Russia — State-sponsored. The tradecraft is not the preserve of criminal crews.
Defining tradecraft
Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.
- Multi-Factor Authentication Request Generation 3 groups — credential-access — MFA request generation — push fatigue.
- Phishing: Spearphishing Voice 1 group — initial-access — Spearphishing by voice.
- Phishing for Information: Spearphishing Voice 2 groups — reconnaissance — Voice-based information elicitation, usually against a help desk.
- User Execution: Malicious Copy and Paste 3 groups — execution — Malicious copy and paste — ClickFix and its variants.
Further reading
- Fake IT support calls on Microsoft Teams are ending in ransomware Ransomware — 2026-07-29
- Hackers are phishing employees through Microsoft Teams, not email Nation-State — 2026-06-10
- Scattered Spider is not one gang but a sprawling cybercrime movement Ransomware — 2026-07-07
- Phishing now starts most intrusions as attackers beat MFA Cyber Incidents — 2026-07-29
- DEV-0537 (LAPSUS$): Social Engineering, SIM Swapping, and Insider Recruitment Power a Pure Extortion and Destruction Campaign Cyber Incidents — 2026-02-16
Recent activity
The most recent incidents in our log attributed to the groups above, from the last twelve months.
- Mayer Brown 2026-08-07 · Silent Ransom Group
- Club One Casino 2026-08-06 · 3AM
- Lumenis Ltd. 2026-08-02 · ShinyHunters
- Alcon Inc. 2026-08-02 · ShinyHunters
- Questel SAS 2026-08-02 · ShinyHunters
- Moses & Singer 2026-08-02 · Silent Ransom Group
- BH Security, LLC. (brinkshome.com) 2026-07-27 · ShinyHunters
- RingCentral, Inc. 2026-07-27 · ShinyHunters
- Ernst & Young 2026-07-27 · ShinyHunters
- While ownership has changed over the years 2026-07-18 · 3AM
- Abbott owned Exact Sciences Corporation 2026-07-15 · ShinyHunters
- Fluke Corporation 2026-07-01 · ShinyHunters
- Ingram Content Group, Inc. 2026-07-01 · ShinyHunters
- Guardian Barrier Services 2026-06-29 · 3AM
- acemacon.org 2026-06-28 · 3AM
- NAIC.org 2026-06-18 · ShinyHunters
- Amazon owned OneMedical.com 2026-06-18 · ShinyHunters
- icsecurity.com 2026-06-18 · ShinyHunters
- He..t S..it. 2026-06-17 · Silent Ransom Group
- He..t S..t. 2026-06-16 · Silent Ransom Group
Our coverage
The 12 most recent of 32 briefings that mention a member of this collection.
- Attackers weaponize most public exploits within 48 hours 2026-08-03
- Russian hackers hijack hotel Wi-Fi to bug travelers 2026-08-01
- Critical VMware bugs let attackers take over virtual server fleets 2026-07-30
- Extortion crew claims Ernst and Young, RingCentral and Brinks Home 2026-07-29
- Abbott probes two breaches as extortion gangs claim patient data theft 2026-07-20
- North Korean hackers hide malware in SVG flags to trap developers 2026-07-17
- DragonForce ransomware posts more than 20 victims in three days 2026-07-17
- ShinyHunters leaks data on 2.3 million Moody Bible supporters 2026-07-14
- Access broker exploits Citrix bug to plant DragonForce ransomware 2026-07-10
- Scattered Spider is not one gang but a sprawling cybercrime movement 2026-07-07
- Critical Oracle, Kemp, and Linux flaws come under active attack 2026-07-06
- Attackers hijack Microsoft 365 accounts using Microsoft's own login page 2026-07-06
How this list was chosen. Selected by ATT&CK technique — T1621, T1566.004, T1598.004 and T1204.004 — then widened by hand to groups whose social-engineering tradecraft is documented in our own reporting or a cited vendor report even where the mapping has not caught up. Half this roster is not currently filing leak-site claims: Black Basta's last claim in our log is from January 2025 and Scattered Spider's only recorded incident is from 2023, so the activity block below is dominated by a handful of members and is not a measure of the set. LAPSUS$ is deliberately absent pending a source-quality review of its incident rows. Every leak-site claim is a claim, not a confirmed breach.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.