Social-Engineering Intrusion Sets

Some intrusion sets are defined by what they exploit. These are defined by whom they talk to.

Of the threat actors we hold any ATT&CK mapping for, only seven carry a technique whose subject is a human being rather than a system — MFA request generation, spearphishing by voice, or malicious copy-and-paste. Those seven sit across three actor types and five origins, which means the site's own filters actively take this set apart: /threat-actors can sort by type, by threat level and by whether a group is popular or new, and none of those controls can express "talks its way in".

The roster below is not those seven. It is wider, because the mapping lags the reporting, and it is also narrower: two of the seven are absent, and so is the only one of them we classify as a hacktivist — which is why the groups listed here span two actor types rather than three.

State the denominator with the finding: fewer than a third of the groups we track carry any ATT&CK mapping at all, so a group's absence from this list is a statement about our coverage and not about its tradecraft. The page leads with the techniques and tooling these groups share, because that comparison is the thing a single-axis page cannot produce, and it moves as the mapping improves.

All collections

What these have in common

Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.

ATT&CK techniques

Shared tooling

Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.

Peak weeks

The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.

Groups

Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.

Defining tradecraft

Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.

Further reading

Recent activity

The most recent incidents in our log attributed to the groups above, from the last twelve months.

Our coverage

The 12 most recent of 32 briefings that mention a member of this collection.

How this list was chosen. Selected by ATT&CK technique — T1621, T1566.004, T1598.004 and T1204.004 — then widened by hand to groups whose social-engineering tradecraft is documented in our own reporting or a cited vendor report even where the mapping has not caught up. Half this roster is not currently filing leak-site claims: Black Basta's last claim in our log is from January 2025 and Scattered Spider's only recorded incident is from 2023, so the activity block below is dominated by a handful of members and is not a measure of the set. LAPSUS$ is deliberately absent pending a source-quality review of its incident rows. Every leak-site claim is a claim, not a confirmed breach.

Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.

Read the full analysis on IntelFusions