Threat Actor

GCMAN

Also known as: GCMAN

[GCMAN](https://attack.mitre.org/groups/G0036) is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services. (Citation: Securelist GCMAN)

2
Techniques

Properties

stix_id
intrusion-set--0ea72cd5-ca30-46ba-bc04-378f701c658f
signal_observed_at
2026-09-11T17:54:59+00:00
type
intrusion-set

MITRE ATT&CK Techniques (2)

SSH

Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary ma

VNC

Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to remotely control machines using Virtual Network Computing (VNC). V

Explore this actor's full graph with Ninja Signal

GCMAN — Threat Actor Profile — Ninja Signal | Ninja Signal