Poseidon Group is a Portuguese-speaking cybercrime threat actor known for Windows-focused post-compromise activity involving discovery, credential access, and defense evasion. The group has been associated with reconnaissance of local and domain environments, including enumeration of administrator accounts, running processes, and services. Reported tradecraft includes use of PowerShell-based components, account discovery against Active Directory environments, and attempts to spoof antivirus-related processes as a self-protection measure. Observed behavior attributed to Poseidon Group aligns with common enterprise intrusion workflows: execution through PowerShell, discovery of privileged accounts on local systems and across the network, process and service enumeration, and efforts to obtain credentials, including unsecured credentials and operating system credential material. Public ATT&CK-style mappings associated with the group include PowerShell execution, shared modules, unsecured credentials, OS credential dumping, process discovery, service discovery, and domain account discovery. The name "Poseidon" also appears in unrelated contexts and should be disambiguated carefully. It has been used as an internal operation name in activity attributed to the North Korea-linked Konni APT, and it also appears in the lineage of Poseidon Stealer, a macOS-focused criminal stealer later rebranded as Odyssey. Those references do not by themselves establish that Poseidon Group is the same entity as Konni or the operators of Poseidon Stealer. High-confidence reporting supports treating Poseidon Group as a distinct cybercrime actor name unless additional corroboration links the identities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Referenced as a threat actor associated with credential access behavior, specifically techniques involving unsecured credentials and OS credential dumping in the context of LAPS password gathering via PowerShell.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.