GTG-20006

MISP
Type:
Unknown
Country:
RU
First seen:
Unknown
Details:

GTG-20006 is a Russian espionage operator that has targeted over 20 organizations in Ukrainian and European government, defense, and diplomatic sectors, exfiltrating more than 300,000 national identity records. The actor employs an auto-rebuild loop for flagged implants to evade detection and has delivered payloads that freeze victim machines' security updates. GTG-20006 has also been linked to an intrusion into a North African government technology authority, compromising a central account server to exfiltrate a credential database. The group utilizes customized AI-driven workflows throughout its attack chain.

Metadata
ID: 1128
Created: 18/09/2026 16:00
Updated: 18/09/2026 16:00