Threat landscape — insurance
Essential information
- Published
- 27/05/2026 15:46
- Modified
- —
- Confidence
- 100/100
- Report type(s)
- threat-report
- Related entities
- 11 intrusion sets (apt), 199 techniques (mitre)
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Intrusion sets (APT) (11)
-
The MITRE Corporation Confidence 100
[Scattered Spider](https://attack.mitre.org/groups/G1015) is a native English-speaking cybercriminal group active since at least 2022. (Citation: CrowdStrike Scattered Spider Profile) (Citation: MSTIC Octo Tempest Operations October 2023) The group initially …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
FIN8 SyssphinxThe MITRE Corporation Confidence 100
[FIN8](https://attack.mitre.org/groups/G0061) is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 00:33 · Modified 27/05/2026 15:52
-
Ransomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 08:53 · Modified 16/06/2026 19:48 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 16:02 · Modified 27/05/2026 15:52
-
POLONIUM Plaid RainThe MITRE Corporation Confidence 100
[POLONIUM](https://attack.mitre.org/groups/G1005) is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2022. Security researchers assess …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:51 · Modified 27/05/2026 15:52
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:28 · Modified 27/05/2026 15:52
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:53 · Modified 27/05/2026 15:52
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:20 · Modified 27/05/2026 15:52
-
The MITRE Corporation Confidence 100
[RedCurl](https://attack.mitre.org/groups/G1039) is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14
Techniques (MITRE) (199)
-
Adversary-in-the-Middle
-
Process Discovery
-
OS Credential Dumping
-
SSH
-
Establish Accounts
-
Password Guessing
-
Malicious Link
-
Compromise Accounts
-
Develop Capabilities
-
Windows Management Instrumentation
-
Local Data Staging
-
RC Scripts
-
Mark-of-the-Web Bypass
-
Domain Account
-
SMB/Windows Admin Shares
-
Match Legitimate Resource Name or Location
-
Group Policy Modification
-
Valid Accounts
-
Boot or Logon Autostart Execution
-
Web Services
-
Virtualization/Sandbox Evasion
-
Tool
-
T1588.005
-
Network Denial of Service
-
File Deletion
-
Security Software Discovery
-
Input Capture
-
NTDS
-
Multi-hop Proxy
-
Compromise Infrastructure
-
Brute Force
-
Query Registry
-
Permission Groups Discovery
-
Local Email Collection
-
Hidden Files and Directories
-
Forced Authentication
-
Domain Accounts
-
Service Stop
-
Lateral Tool Transfer
-
Masquerading
-
Process Injection
-
Scheduled Task/Job
-
Non-Standard Port
-
Domain Account
-
Hide Artifacts
-
Encrypted Channel
-
Process Hollowing
-
Python
-
Exploitation for Credential Access
-
Use Alternate Authentication Material
-
Credentials from Web Browsers
-
Browser Information Discovery
-
JavaScript
-
T1600
-
T1080
-
Transfer Data to Cloud Account
-
Keylogging
-
Exfiltration Over Alternative Protocol
-
Steganography
-
Disable Windows Event Logging
-
Email Account
-
Bypass User Account Control
-
Indicator Removal
-
Phishing
-
Defacement
-
Gather Victim Identity Information
-
Web Protocols
-
Inhibit System Recovery
-
Windows Remote Management
-
Credentials from Password Stores
-
Shortcut Modification
-
Email Accounts
-
Spearphishing Link
-
Rootkit
-
Upload Malware
-
Exploitation of Remote Services
-
PowerShell
-
Proxy
-
Video Capture
-
Credentials In Files
-
Credentials in Registry
-
Exploitation for Privilege Escalation
-
Default Accounts
-
Software Discovery
-
Impair Defenses
-
Data Encoding
-
Remote Data Staging
-
Asymmetric Cryptography
-
System Network Configuration Discovery
-
Malicious File
-
Data from Cloud Storage
-
Vulnerabilities
-
Modify Registry
-
Scheduled Task
-
Systemd Service
-
Spearphishing Attachment
-
Internal Defacement
-
Disable or Modify Cloud Firewall
-
User Execution
-
Data Encrypted for Impact
-
Windows Command Shell
-
Mshta
-
Email Collection
-
Native API
-
Remote System Discovery
-
T1110.003
-
Private Keys
-
Acquire Infrastructure
-
Rundll32
-
Resource Hijacking
-
Protocol Tunneling
-
Archive Collected Data
-
Password Cracking
-
Data from Local System
-
Token Impersonation/Theft
-
Create or Modify System Process
-
Local Accounts
-
Malware
-
Obfuscated Files or Information
-
Exfiltration to Cloud Storage
-
Hijack Execution Flow
-
System Services
-
Exploit Public-Facing Application
-
Spearphishing via Service
-
Ingress Tool Transfer
-
Archive via Utility
-
Data from Network Shared Drive
-
Password Managers
-
Social Media Accounts
-
Non-Application Layer Protocol
-
Unix Shell
-
Account Access Removal
-
Access Token Manipulation
-
Remote Access Tools
-
System Shutdown/Reboot
-
Account Manipulation
-
Network Service Discovery
-
Indirect Command Execution
-
Event Triggered Execution
-
T1098.003
-
Create Account
-
T1110.004
-
LSASS Memory
-
Command and Scripting Interpreter
-
Domains
-
Visual Basic
-
T1006
-
External Remote Services
-
Steal Web Session Cookie
-
Endpoint Denial of Service
-
Exfiltration Over Unencrypted Non-C2 Protocol
-
Phishing for Information
-
Bidirectional Communication
-
Domain Groups
-
Account Discovery
-
Cloud Accounts
-
Registry Run Keys / Startup Folder
-
Asynchronous Procedure Call
-
Spearphishing Link
-
Supply Chain Compromise
-
Standard Encoding
-
System Owner/User Discovery
-
Drive-by Compromise
-
T1016.001
-
System Checks
-
Trusted Relationship
-
Web Service