logo

Threat Spotlight: Group 72

ID: 27fbd98e-e675-4ed6-9165-6ddc7c9b010b

STIX ID: report--27fbd98e-e675-4ed6-9165-6ddc7c9b010b

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2014-10-17

Last Modified Date: 2014-10-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Talos describes ‘Group 72’ (associated with Operation SMN/Axiom) as a sophisticated, well-funded threat actor targeting high-value organizations in manufacturing, aerospace, defense and media across the US and parts of Asia using watering-hole attacks, spear-phishing, SQL injection and exploit-based initial access (several CVEs cited) to deploy multiple remote access trojans (Ghost RAT, Poison Ivy, HydraQ, HiKit, Zxshell, DeputyDog, Derusbi, PlugX); the report includes IoCs (ClamAV names, Snort signature IDs), domain/email registration patterns, and recommended product protections.