Social-Engineering Intrusion Sets
Some intrusion sets are defined by what they exploit. These are defined by whom they talk to.
Of the threat actors we hold any ATT&CK mapping for, only eight carry a technique whose subject is a human being rather than a system — MFA request generation, spearphishing by voice, or malicious copy-and-paste. Those eight sit across three actor types and five origins, which means the site's own filters actively take this set apart: /threat-actors can sort by type, by threat level and by whether a group is popular or new, and none of those controls can express "talks its way in".
The roster below is not those eight. It is wider, because the mapping lags the reporting, and it is also narrower: two of the eight are absent, and so is the only one of them we classify as a hacktivist — which is why the groups listed here span two actor types rather than three.
State the denominator with the finding: fewer than a third of the groups we track carry any ATT&CK mapping at all, so a group's absence from this list is a statement about our coverage and not about its tradecraft. The page leads with the techniques and tooling these groups share, because that comparison is the thing a single-axis page cannot produce, and it moves as the mapping improves.
- Curated entries: 20
- Incidents attributed in the last 90 days: 74
- 43 linked briefings
What these have in common
Techniques and tooling shared by more than one of the groups below. Each row shows how many of the groups here carry it, against how many of the groups we hold that kind of data for at all. Ordered by the gap between those two shares — so what leads is what is distinctive about this set, not what is common to everyone.
ATT&CK techniques
- Financial Theft (T1657) 4/7 here · 19/194 tracked
- Acquire Infrastructure: Domains (T1583.001) 5/7 here · 47/194 tracked
- Obtain Capabilities: Tool (T1588.002) 6/7 here · 81/194 tracked
- Exfiltration Over Web Service (T1567) 3/7 here · 7/194 tracked
- Remote Access Tools: Remote Desktop Software (T1219.002) 3/7 here · 11/194 tracked
- Valid Accounts: Cloud Accounts (T1078.004) 3/7 here · 13/194 tracked
- Phishing: Spearphishing via Service (T1566.003) 3/7 here · 14/194 tracked
- Remote Access Tools (T1219) 3/7 here · 15/194 tracked
- Social Engineering: Impersonation (T1684.001) 3/7 here · 16/194 tracked
- Remote Services: SSH (T1021.004) 3/7 here · 21/194 tracked
Shared tooling
- Tor 3/10 here · 7/255 tracked
- Cobalt Strike 5/10 here · 68/255 tracked
- BeaverTail 2/10 here · 2/255 tracked
- InvisibleFerret 2/10 here · 2/255 tracked
- QakBot 2/10 here · 5/255 tracked
- SystemBC 2/10 here · 12/255 tracked
- AdFind 2/10 here · 15/255 tracked
- Impacket 2/10 here · 24/255 tracked
- Rclone 2/10 here · 31/255 tracked
- PsExec 3/10 here · 64/255 tracked
Tooling counts come from the ATT&CK software catalogue, which includes dual-use administrative utilities as well as bespoke malware.
Peak weeks
The busiest single week of leak-site publication for each group here, as a share of everything it has ever posted. Read the last figure first: a peak that lands on day zero is a new leak site publishing its backlog, not a wave of fresh victims. Dates are publication dates, not dates of compromise.
- ShinyHunters 42 of 157 claims in the week of 2025-09-29 · 26.8% of lifetime output · peaked in its DEBUT week
Groups
Incident counts are attributions in our own log, which is built from ransomware leak-site claims and public breach notices. Espionage actors legitimately show none.
- Scattered Spider 1 incident — Ransomware · Unknown — 2023-09-11 — Help-desk impersonation and SIM swap; the reference implementation.
- Storm-1811 0 incidents — Ransomware · Unknown — Teams vishing into remote-access tooling.
- ShinyHunters 157 incidents — Ransomware · Unknown — 2026-09-13 — Credential-led data extortion at scale.
- Silent Ransom Group 56 incidents — Ransomware · Unknown — 2026-09-04 — Callback phishing.
- Black Basta 194 incidents — Ransomware · Russia — 2025-01-11 — Teams-based help-desk impersonation. Dormant in our log since January 2025.
- 3AM 27 incidents — Ransomware · Unknown — 2026-08-30 — Vishing-led intrusions; the tradecraft here is asserted in prose, not mapped.
- FIN7 0 incidents — Ransomware · Russia — Long-running social-engineering and lure development.
- Contagious Interview 0 incidents — APT · North Korea — A fake job interview is social engineering with a DPRK revenue motive.
- Famous Chollima 0 incidents — APT · North Korea — Fraudulent employment as an access technique.
- Jasper Sleet 0 incidents — APT · North Korea — Same tradecraft, separate designation.
- APT29 0 incidents — APT · Russia — State-sponsored. The tradecraft is not the preserve of criminal crews.
Defining tradecraft
Techniques a curator named as definitional for this set — a different claim from the computed list above, which is whatever the members happen to share.
- Multi-Factor Authentication Request Generation 3 groups — credential-access — MFA request generation — push fatigue.
- Phishing: Spearphishing Voice 2 groups — initial-access — Spearphishing by voice.
- Phishing for Information: Spearphishing Voice 2 groups — reconnaissance — Voice-based information elicitation, usually against a help desk.
- User Execution: Malicious Copy and Paste 3 groups — execution — Malicious copy and paste — ClickFix and its variants.
Further reading
- Fake IT support calls on Microsoft Teams are ending in ransomware Ransomware — 2026-07-29
- Hackers are phishing employees through Microsoft Teams, not email Nation-State — 2026-06-10
- Scattered Spider is not one gang but a sprawling cybercrime movement Ransomware — 2026-07-07
- Phishing now starts most intrusions as attackers beat MFA Cyber Incidents — 2026-07-29
- DEV-0537 (LAPSUS$): Social Engineering, SIM Swapping, and Insider Recruitment Power a Pure Extortion and Destruction Campaign Cyber Incidents — 2026-02-16
Recent activity
The most recent incidents in our log attributed to the groups above, from the last twelve months.
- Kimberly-Clark 2026-09-13 · ShinyHunters
- State of Florida DMV 2026-09-07 · ShinyHunters
- Medela.com 2026-09-07 · ShinyHunters
- Note to mr. databroker1 NEXUS DL Service 2026-09-04 · ShinyHunters
- H... C... 2026-09-04 · Silent Ransom Group
- A...en 2026-09-03 · Silent Ransom Group
- P... S... 2026-09-03 · Silent Ransom Group
- Katten Muchin Rosenman 2026-09-03 · Silent Ransom Group
- G... ...g 2026-09-02 · Silent Ransom Group
- S... M... 2026-09-02 · Silent Ransom Group
- Greenberg Traurig 2026-09-02 · Silent Ransom Group
- Holland & Knight 2026-09-01 · Silent Ransom Group
- Twin States News 2026-08-30 · 3AM
- Neogen Corporation 2026-08-29 · ShinyHunters
- Jack Henry & Associates 2026-08-28 · ShinyHunters
- McKesson Corporation 2026-08-28 · ShinyHunters
- Elekta AB 2026-08-28 · ShinyHunters
- G... T... 2026-08-27 · Silent Ransom Group
- Ne...n M... 2026-08-27 · Silent Ransom Group
- H... L... 2026-08-26 · Silent Ransom Group
Our coverage
The 12 most recent of 43 briefings that mention a member of this collection.
- North Korea's hacking machine is bigger than Lazarus 2026-09-07
- ShinyHunters claims 284 million records from McKesson 2026-08-31
- Drug distribution giant McKesson confirms data theft 2026-08-29
- North Korean fake workers move into healthcare and sales 2026-08-28
- 25 US law firms are on one extortion crew's leak site 2026-08-28
- Spies and ransomware crews exploit the same edge devices 2026-08-26
- Abandoned e-learning platform has 13 flaws and no patch 2026-08-20
- Russia's spies phish by asking you to link your WhatsApp 2026-08-20
- State hackers now log in instead of dropping malware 2026-08-20
- North Korean fake hires used ChatGPT to pass interviews 2026-08-18
- Ransomware crews can hide their tracks in ESX logs 2026-08-07
- Attackers weaponize most public exploits within 48 hours 2026-08-03
How this list was chosen. Selected by ATT&CK technique — T1621, T1566.004, T1598.004 and T1204.004 — then widened by hand to groups whose social-engineering tradecraft is documented in our own reporting or a cited vendor report even where the mapping has not caught up. Half this roster is not currently filing leak-site claims: Black Basta's last claim in our log is from January 2025 and Scattered Spider's only recorded incident is from 2023, so the activity block below is dominated by a handful of members and is not a measure of the set. LAPSUS$ is deliberately absent pending a source-quality review of its incident rows. Every leak-site claim is a claim, not a confirmed breach.
Coverage. Membership here is curated and changes only when a person changes it; every count on this page is computed live. Incident figures come from ransomware leak-site claims and public breach notices, which under-represent espionage, so a group with no incidents is not a quiet group — it is a group our incident sources do not see.