GTG-20006
MISP
Type:
Unknown
Unknown
Country:
RU
RU
First seen:
Unknown
Unknown
Details:
GTG-20006 is a Russian espionage operator that has targeted over 20 organizations in Ukrainian and European government, defense, and diplomatic sectors, exfiltrating more than 300,000 national identity records. The actor employs an auto-rebuild loop for flagged implants to evade detection and has delivered payloads that freeze victim machines' security updates. GTG-20006 has also been linked to an intrusion into a North African government technology authority, compromising a central account server to exfiltrate a credential database. The group utilizes customized AI-driven workflows throughout its attack chain.
References (1)
Metadata
| ID: | 1128 |
| Created: | 18/09/2026 16:00 |
| Updated: | 18/09/2026 16:00 |