🇷🇺

NoName057

APT Group 2 zero-day CVEs

Also Known As 4 names

05716nnm Nnm05716 NoName057(16) NoName05716

Target Countries 74

Countries highlighted in red

United Arab Emirates Armenia Argentina Austria Australia Azerbaijan Bangladesh Belgium Belarus Canada Switzerland China Cuba Cyprus Czech Republic Germany Denmark Algeria Estonia Egypt Spain Finland France United Kingdom Georgia Greece Croatia Hungary Indonesia Ireland Israel India Iraq Iceland Italy Japan Kenya Republic of Korea Lebanon Liberia Lithuania Luxembourg Latvia Morocco Republic of Moldova Myanmar Mongolia Mexico Malaysia Nigeria Nicaragua Netherlands Norway Peru Pakistan Poland Portugal Romania Russian Federation Saudi Arabia Sudan Sweden Singapore Slovenia Slovakia Senegal Chad Thailand Turkey Province of China Taiwan Ukraine United States Yemen South Africa

Sectors Targeted

Defense Industry Water Transportation 483 Arms Factories Services Military and financial services Religious, Grantmaking, Civic, Professional, and Similar Organizations 813 Agriculture Automotive Private Sector Manufacturing Financial Sector Ship Building and Repairing 336611 Multiple Sectors (Public and Private) Water Supply Government Infrastructure smart city platforms energy financial Multiple (depending on the websites targeted) Utilities 22 Infrastructure Critical Infrastructure Energy Providers Arms Industry Indian government and financial sectors Legal Airport Industrial machinery Cryptocurrency Online Commerce banking Commercial entities E-commerce Internet Publishing and Broadcasting and Web Search Portals 51913 Political Parties Arms Manufacturers Energy Digital Infrastructure Web Hosting Government institutions Management, Scientific, and Technical Consulting Services 5416 Food Services and Drinking Places 722 Transportation Health Care and Social Assistance 62 financial services insurance Service Providers Education Public Administration 92 Automobile Dealers 4411 Multiple Grantmaking and Giving Services 8132 Food Freight Transportation Arrangement 48851 Food and Beverage Multiple sectors (websites) military Enterprise IT enterprise websites and applications Technology Business services Motion Picture and Video Production 51211 Computing Infrastructure Providers Political Health Services Food Manufacturing 311 Services providers Postal Services Maritime Utilities Enterprise Electric Power Generation 22111 Journalism airport Pharmaceutical Power Suppliers Agriculture, Forestry, Fishing and Hunting 11 Authorities government institutions Justice, Public Order, and Safety Activities 9221 Publishing Industries (except Internet) 511 Gaming Public Services Biotechnology Retail Business, Professional, Labor, Political, and Similar Organizations 8139 Aerospace Banking Couriers and Express Delivery Services 492110 Computer Systems Design and Related Services 5415 Food and beverages Computer Systems Design Services 541512 Business Public Transportation Social Media BFSI Logistics Law Enforcement telecommunications finance Industrial Manufacturing Public Transport National Security and International Affairs 928 Aerospace & Defense Government Institutions Shipping Insurance Carriers and Related Activities 524 service provider IT media Other Information Services 519 Financial Service Provider Commodity Contracts Intermediation 523160 Government; Public Administration; Aviation; Retail; Logistics; Energy; Financial; Healthcare Data Processing agriculture Academic Accommodation and Food Services 72 transportation Healthcare Public Administration Government (Defence) Public Utilities energy and defence Defence Hospitality Water Treatment Facilities Finance Commercial Private Companies NAICS:44 44 Public Sector government Truck Transportation 484 financial services organizations National Security and International Affairs 9281 education) Shipbuilding Management of Companies and Enterprises 55 Nuclear Political Organizations Communications Media Space Research and Technology 927 Multiple Sectors and defense systems Organizations Telecommunications Various (including real estate public utilities City Administration Diplomatic Institutions Judiciary and defense sectors retail energy providers Other Services (except Public Administration) 81 Telecommunications 517 Tech Firms General Public Energy & Utilities Couriers and Express Delivery Services 4921 manufacturing Telecom food Airports Business Services Information 51 and defence sectors Defense and critical infrastructure. including government Finance and Insurance 52 NAICS:31 31 Monetary Authorities-Central Bank 521 Industrial Justice, Public Order, and Safety Activities 922 Various Critical Infrastructure (water Water Semiconductor Industry Commercial Banking 52211 financial entities Semiconductor Computer and Electronic Product Manufacturing 334 Credit Unions 52213 Software Publishers 5112 Various sectors targeted by hacktivists Employment Placement Agencies and Executive Search Services 56131 Defence Contractors communications Hotels (except Casino Hotels) and Motels 721110 Chemical Manufacturing 325 defense sectors Financial Institutions airports Government/Political Electronic Shopping and Mail-Order Houses 4541 Service providers IT Infrastructure Computer Systems Design and Related Services 54151 Professional, Scientific, and Technical Services 54 Rail Transportation 482 Transport Government Government services NAICS:48 48 Winemaking Legal Services 5411 logistics Aviation Governmental Insurance e-commerce Broadcasting Defense Industrial Base Postal Service healthcare Arts, Entertainment, and Recreation 71 Educational Services 61 Air Transportation 481 Critical infrastructure City Administrations Public services energy) Financial Services business services

Details

Origin 🇷🇺 RU
Last Updated 18 Dec 2025

Malware Families 55

wannacryptor
backswap
ZLOADER
hermeticwiper
REVENGERRAT
hupigon
huskloader
expiro
redcap
powerat
zeus_openssl
havex_rat
dofloo
graftor
pykspa
TINY
NJRAT
limerat
win.qhost
kuaibu8
feodo
troublegrabber
CRYXOS
virut
backnet
webmonitor
sarhust
agent_tesla
EMOTET
agent_btz
Asprox
mikey
AZORULT
zgrat
outcrypt
zhmimikatz
WACATAC
blacknix_rat
networm
SMOKELOADER
TRICKBOT
blacknet_rat
nircmd
mokes
rctrl
unidentified_069
teambot
kuluoz
wannaren
zeus_action
bfbot
unidentified_071
P2P ZeuS
lokipws
revenge_rat

MITRE ATT&CK 150

T1001 - Data Obfuscation T1001.003 T1003 T1005 T1012 T1014 - Rootkit T1016 - System Network Configuration Discovery T1017 - Application Deployment Software T1023 - Shortcut Modification T1027 - Obfuscated Files or Information T1031 - Modify Existing Service T1035 T1036 - Masquerading T1038 - DLL Search Order Hijacking T1041 - Exfiltration Over C2 Channel T1043 T1045 - Software Packing T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1049 - System Network Connections Discovery T1053 - Scheduled Task/Job T1055 - Process Injection T1056 - Input Capture T1056.001 - Keylogging T1057 T1059 - Command and Scripting Interpreter T1059.007 - JavaScript T1060 - Registry Run Keys / Startup Folder T1068 - Exploitation for Privilege Escalation T1070 T1070.003 T1071 - Application Layer Protocol T1071.001 - Web Protocols T1071.002 T1071.003 - Mail Protocols T1071.004 - DNS T1078 - Valid Accounts T1081 - Credentials in Files T1082 - System Information Discovery T1083 - File and Directory Discovery T1087 - Account Discovery T1088 - Bypass User Account Control T1090 - Proxy Use T1094 T1095 - Non Application Layer Protocol T1100 T1102 - Web Service T1105 - Ingress Tool Transfer T1106 - Native API T1110 - Brute Force T1110.002 - Password Cracking T1111 - Two-Factor Authentication Interception T1112 - Modify Registry T1113 - Screen Capture T1114 - Email Collection T1114.002 - Remote Email Collection T1119 - Automated Collection T1123 - Audio Capture T1125 - Video Capture T1129 - Shared Modules T1132 - Data Encoding T1132.001 T1133 - External Remote Services T1134 T1134.001 T1135 T1140 - Deobfuscate/Decode Files or Information T1143 - Hidden Window T1147 T1155 - AppleScript T1156 - Malicious Shell Modification T1176 - Browser Extensions T1179 T1184 T1190 - Exploit Public-Facing Application T1192 - Spearphishing Link T1193 - Spearphishing Attachment T1194 - Spearphishing via Service T1202 - Indirect Command Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1211 - Exploitation for Defense Evasion T1218 - Signed Binary Proxy Execution T1410 T1412 - Capture SMS Messages T1415 T1445 - Abuse of iOS Enterprise App Signing Key T1448 - Carrier Billing Fraud T1449 - Exploit SS7 to Redirect Phone Calls/SMS T1450 - Exploit SS7 to Track Device Location T1453 T1454 - Malicious SMS Message T1459 - Device Unlock Code Guessing or Brute Force T1464 - Jamming or Denial of Service T1491 - Defacement T1493 - Transmitted Data Manipulation T1496 - Resource Hijacking T1497 - Virtualization/Sandbox Evasion T1497.002 T1498 - Network Denial of Service T1498.001 T1498.002 - Reflection Amplification T1499 - Endpoint Denial of Service T1503 - Credentials from Web Browsers T1504 T1505 T1518 T1518.001 T1523 T1534 - Internal Spearphishing T1546 T1546.015 T1547 T1548 T1560 - Archive Collected Data T1562.001 T1563 T1566 - Phishing T1567 - Exfiltration Over Web Service T1568 T1571 T1573 - Encrypted Channel T1574 - Hijack Execution Flow T1583 - Acquire Infrastructure T1583.002 - DNS Server T1583.005 - Botnet T1584 - Compromise Infrastructure T1584.005 T1588 - Obtain Capabilities T1588.004 T1589 - Gather Victim Identity Information T1591 - Gather Victim Org Information T1595 - Active Scanning T1598 - Phishing for Information T1602 - Data from Configuration Repository T1608 - Stage Capabilities TA0001 - Initial Access TA0002 - Execution TA0003 TA0004 - Privilege Escalation TA0005 - Defense Evasion TA0006 - Credential Access TA0007 TA0009 TA0011 - Command and Control TA0029 - Privilege Escalation TA0034 TA0037 TA0040 - Impact TA0043 - Reconnaissance