Gadolinium

Threat Actor updated 4 months ago (2024-05-04T20:17:14.647Z)
Download STIX
Preview STIX
Gadolinium is a sophisticated threat actor group, operating on a global scale for nearly a decade with a particular focus on the maritime and health industries. Historically, Gadolinium has utilized custom-crafted malware families that analysts could identify and defend against. However, as security practitioners have adapted their tools and techniques to counter these threats, Gadolinium has shown its adaptability by altering its methods in response. In recent years, it has begun to modify parts of its toolchain to use open-source toolkits, making its activities more difficult to track and obfuscating its malicious operations. In April 2020, Microsoft's Identity Security team took significant action against Gadolinium by suspending 18 Azure Active Directory applications identified as part of Gadolinium’s PowerShell Empire infrastructure. This proactive measure was beneficial to customers, providing protection without requiring any action on their end. Despite such interventions, Gadolinium continues to evolve its tactics in pursuit of its objectives, demonstrating a persistent threat to cybersecurity worldwide. The group's modus operandi often involves installing web shells on legitimate websites for command and control or traffic redirection purposes. As with most threat groups, Gadolinium keeps an eye on the tools and techniques of security practitioners, seeking new methods they can adopt or modify to create novel exploit methods. The continual evolution of Gadolinium's tactics underscores the need for ongoing vigilance and innovation among security practitioners to protect against this pernicious threat.
Description last updated: 2024-01-18T05:15:31.618Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Gadolinium Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
8 months ago
Search | arXiv e-print repository
MITRE
2 years ago
Microsoft Security—detecting empires in the cloud - Microsoft Security Blog