Threat Actor
GCMAN
Also known as: GCMAN
[GCMAN](https://attack.mitre.org/groups/G0036) is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services. (Citation: Securelist GCMAN)
2
Techniques
Properties
- stix_id
- intrusion-set--0ea72cd5-ca30-46ba-bc04-378f701c658f
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (2)
▸
SSH
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary ma
▸
VNC
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to remotely control machines using Virtual Network Computing (VNC). V
Explore this actor's full graph with Ninja Signal