APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
TA542 (aka Mealybug, Emotet) · APT Atlas
Actors
/
Cybercrime
/
Unattributed
TA542
G0126
CRIME
?? · Unattributed
AKA
Mealybug · Emotet
CrowdStrike
:
MUMMY SPIDER
Microsoft
:
DEV-0184
MITRE
:
G0126
Secureworks
:
GOLD CRESTWOOD
Emotet botnet operators.
Targets
12
Sectors
6
Threat types
1
GIRs covered
0/480
Active since
2014
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 2 other aliases
Open Rosetta Stone
CrowdStrike
MUMMY SPIDER
Microsoft
DEV-0184
MITRE
G0126
Proofpoint
TA542
Secureworks
GOLD CRESTWOOD
UNATTRIBUTED ALIASES
Mealybug
Emotet
Victimology
Geographic footprint · 12 countries
Region filter
Export
origin · unattributed
targeted countries · 12
OCEANIA ·
2
Australia
·
New Zealand
AMERICAS ·
2
Canada
·
United States
EUROPE ·
6
Germany
·
Spain
·
France
·
United Kingdom
·
Italy
·
Poland
ASIA ·
2
Hong Kong
·
Japan
Sectors targeted
6 of 40
Government
100 actors
Financial Services
74 actors
Cryptocurrency
21 actors
Healthcare
47 actors
Retail & Hospitality
33 actors
Hospitality
33 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
RAN · Ransomware
MITRE ATT&CK · 0 techniques
No TTPs mapped yet.
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
0 techniques · layer format 4.5
Related actors
By origin and actor type
FIN10
cybercrime
unattributed · 1 targets · since 2013
FIN2
cybercrime
unattributed · 0 targets · since —
FIN6
cybercrime
Russia · 15 targets · since 2014
APT73
nation-state
unattributed · 0 targets · since —
UNC1543
cybercrime
unattributed · 22 targets · since —
FIN3
cybercrime
unattributed · 1 targets · since —