Gorgon Group is a Pakistan-linked threat actor tracked in ATT&CK as G0078. The group has been associated with spearphishing-led intrusions that rely heavily on malicious Microsoft Office attachments and other socially engineered lures to induce user execution. Its activity has targeted victims in South Asia while also extending beyond the region, indicating a broader victimology than some regionally focused operators. The group is known for using commodity and custom malware, including historical use of NanoCore, to establish remote access and stage follow-on payloads. Observed tradecraft includes delivery of malicious Office documents via email, use of PowerShell for payload download and execution, and command-shell activity to retrieve or launch additional components. Gorgon Group has used hidden PowerShell execution, including WindowStyle-hidden variants, to reduce user visibility during execution. On compromised Windows systems, Gorgon Group malware has demonstrated persistence through creation of Registry Run entries and Startup-folder shortcut mechanisms. The group has also modified Microsoft Office-related registry settings to weaken or deactivate security protections, and has attempted to disable defensive controls in Microsoft Office and Windows Defender. Additional observed behaviors include Base64 decoding of payload content before writing it to disk and downloading further files from command-and-control infrastructure. Aliases include Gorgon, gorgon_group, and the_gorgon_group. The actor is generally characterized by phishing-centric initial access, straightforward but effective Windows persistence, PowerShell-enabled staging, registry modification for both persistence and defense evasion, and use of readily available malware tooling alongside bespoke intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Referenced as a threat actor associated with registry modification behavior (MITRE ATT&CK T1112: Modify Registry) in the context of this detection analytic.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.