Threadlinqs IntelligenceStart free

Threat actorRussiaTracked since 2026-09

GTG-20006

Also known as:GTG-10007GTG-50014

As of 2026-10-09, GTG-20006 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning apt. Also known as GTG-10007, GTG-50014. ATT&CK coverage spans 31 techniques across 12 tactics in 2 of 2 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1078.004 (Cloud Accounts), T1528 (Steal Application Access Token).

Tracked threats
21 critical · 1 high
First seen
2026-09-12
Last seen
2026-10-09
ATT&CK techniques
31across 2 of 2 threats
Related CVEs
0None referenced
Attribution
RussiaNation or origin
Nation: Russia · 2 tracked threat(s) · Categories: APT

Activity timeline

GTG-20006 appears in 2 tracked threats between and ; the busiest month was 2026-09 with 1 report.

ATT&CK techniques observed

31 techniques observed across 2 of 2 tracked threats · Initial Access (6), Credential Access (4), Reconnaissance (4), Collection (3), Execution (3), Persistence (3)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 2 of 2 tracked threats
  • T1078.004 Cloud Accounts — Initial Accessobserved in 2 of 2 tracked threats
  • T1528 Steal Application Access Token — Credential Accessobserved in 2 of 2 tracked threats
  • T1583.001 Domains — Resource Developmentobserved in 2 of 2 tracked threats
  • T1584.002 DNS Server — Resource Developmentobserved in 2 of 2 tracked threats
  • T1056.001 Keylogging — Credential Accessobserved in 1 of 2 tracked threats
  • T1059.001 PowerShell — Executionobserved in 1 of 2 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 1 of 2 tracked threats
  • T1098.005 Device Registration — Persistenceobserved in 1 of 2 tracked threats
  • T1113 Screen Capture — Collectionobserved in 1 of 2 tracked threats
  • T1114 Email Collection — Collectionobserved in 1 of 2 tracked threats
  • T1114.002 Email Collection: Remote Email Collection — Collectionobserved in 1 of 2 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 1 of 2 tracked threats
  • T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 1 of 2 tracked threats
  • T1199 Trusted Relationship — Initial Accessobserved in 1 of 2 tracked threats

Tracked threats