The Gorgon Group: Slithering Between Nation State and Cybercrime
ID: a4a8fd36-13aa-4822-b6a6-e1eec3e48450
STIX ID: report--a4a8fd36-13aa-4822-b6a6-e1eec3e48450
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2018-12-04
Last Modified Date: 2018-12-04
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzes Gorgon Group, a threat actor whose operations span targeted nation-state campaigns and criminal cybercrime, leveraging shared infrastructure, phishing, and multiple malware families (NjRAT, LokiBot, RemcosRAT, NanoCore) to attack governmental and global targets. The group uses macro-delivery documents, Bitly-based C2 domains, and a mix of open-source downloader tools and embedded payloads, with evidence pointing to a Pakistan nexus and active, ongoing activity in 2018.
