Mining & Metals — Cyber Threat Activity
Mining and metals holds no recorded incidents in our log and one of the thinnest actor graphs here, with 5 groups carrying a researched association: Agrius, ExCobalt, FIN10, Head Mare and Predatory Sparrow. That list is more revealing than its length. It is dominated by operators associated with destructive and politically motivated activity rather than by extortion crews, which matches a sector whose value to an attacker is frequently disruption of a national resource industry rather than payment. Metals producers do appear in industrial ransomware data, where Dragos recorded metals as a mid-sized manufacturing subsector in early 2025, well behind construction and food and beverage, so the criminal volume exists but is modest relative to the sector's economic weight. The exposure that matters is operational. Mines, smelters and processing plants run continuous processes on control systems where an unplanned stop is expensive and, in the case of furnaces and refining, physically damaging rather than merely disruptive. Remote and autonomous operations centres now manage geographically distant sites over network links that concentrate control in one reachable place. Commodity trading and export logistics attach the sector to price-sensitive information worth stealing in its own right. Read the absence of incidents here as a collection limit rather than a finding, note that mining victims are frequently classified under manufacturing or energy in our corpus, and treat the actor associations as published research on each group rather than incidents we have attributed ourselves.
- Recorded incidents: 17
- Incidents, trailing 180 days: 3
- Tracked threat actors: 16
- Malware families: 20
Threat actors targeting Mining & Metals
- Qilin 3 incidents
- BianLian 2 incidents
- INC Ransom 2 incidents
- SafePay 2 incidents
- The Gentlemen 2 incidents
- Akira 1 incident
- Cl0p 1 incident
- FulcrumSec 1 incident
- FunkSec 1 incident
- RansomHub 1 incident
- Sarcoma 1 incident
- Agrius researched targeting
- ExCobalt researched targeting
- FIN10 researched targeting
- Head Mare researched targeting
- Predatory Sparrow researched targeting
Malware used against Mining & Metals
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Mimikatz Tool
- PsExec Tool
- Sliver Tool
- Babuk Malware
- Empire Tool
- ngrok Tool
- ProcDump Tool
- Rclone Tool
- ADRecon Tool
- Apostle Malware
- ASPXSpy Malware
- BFG Agonizer Malware
Where these victims are
- Canada 3
- Chile 3
- United States 2
- Australia 1
- Brazil 1
- Colombia 1
- Germany 1
- Japan 1
- South Africa 1
- Switzerland 1
- United Kingdom 1
Recent incidents
- Las Cenizas 2026-07-31
- Conecsus 2026-07-23
- Analog Gold / Prospector 2026-05-01
- Sociedad Punta del Cobre S.A. 2026-02-02
- KOUEI 2026-02-02
- EASTPLATS.COM 2026-01-25
- Knight Group 2025-12-29
- Josh Steel 2025-12-19
- wachtmann.eu 2025-12-05
- ferrocortes 2025-08-06
- Bauer-Walser AG 2025-04-08
- www.cmsg.cl 2025-02-26
- megamtls.com 2025-02-25
- uniamarmores 2024-12-07
- Gmg Mining Supplies 2024-10-09
- Hunter Dickinson Inc. 2024-09-19
- Northern Minerals Limited 2024-06-03
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.