Threat Group-1314 is a threat actor tracked under the aliases TG_1314 and Threat Group-1314. The group has used compromised domain credentials associated with an endpoint-management platform to move laterally within victim networks. It has also spawned Windows command shells on remote systems to execute commands, including activity involving SMB/Windows administrative shares.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as an annotated actor associated with the detection technique.
Listed in the detection's Annotations section.
Listed as a threat actor associated with Windows Command Shell execution behavior relevant to this detection.
Listed in the detection annotations as a threat actor associated with techniques involving Windows theme files, forced authentication, name resolution poisoning/SMB relay, and SMB/Windows admin shares.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.