Inception
G01003 reportsaliases · Inception · Inception Framework · Cloud Atlas
3
Reports
5
Techniques
3
Tactics
2
Countries
100%
Hunt coverage
3
Aliases
Analyst assessment — key judgments
- Signature techniques: T1589.001 (Credentials), T1593.001 (Social Media), T1213.002 (Sharepoint).
- Primary targeting: US, RU.
- Tooling observed: Storm.
- Steady activity: 1 report(s) in last 30d vs 1 prior (+0%).
- Recent movement: 2 new infrastructure indicator(s), 1 new tool(s) in the last 30 days.
- Hunt coverage 100% of 5 observed techniques (0 gap(s)).
- Assessment confidence: medium (61).
Activity & trend
SteadyLast 30d: 1 vs 1 prior (+0%)· first reported 2026-06-10 · last 2026-09-18
1
7d
1
30d
2
90d
3
All
0.2
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
Dropped (90d+)
T1593.001New infrastructure
thestatebankgroup.comhttp://yqhecvqtdvq6p7duqcgw2qca77spbgakxVulnerabilities in this actor's reporting · 81
- CVE-2008-4128KEV1 rpt
- CVE-2017-7269KEV1 rpt
- CVE-2018-0802KEV1 rpt
- CVE-2018-14558KEV1 rpt
- CVE-2020-8515KEV1 rpt
- CVE-2021-27137KEV1 rpt
- CVE-2021-3156KEV1 rpt
- CVE-2021-31755KEV1 rpt
- CVE-2021-4034KEV1 rpt
- CVE-2023-25717KEV1 rpt
- CVE-2023-4346KEV1 rpt
- CVE-2024-42009KEV1 rpt
- CVE-2025-32432KEV1 rpt
- CVE-2025-3248KEV1 rpt
- CVE-2025-49113KEV1 rpt
- CVE-2025-55182KEV1 rpt
- CVE-2025-66376KEV1 rpt
- CVE-2025-68686KEV1 rpt
- CVE-2026-0257KEV1 rpt
- CVE-2026-0770KEV1 rpt
- CVE-2026-12569KEV1 rpt
- CVE-2026-15409KEV1 rpt
- CVE-2026-15410KEV1 rpt
- CVE-2026-16232KEV1 rpt
- CVE-2026-16812KEV1 rpt
Overview
Analyst triage
Intelligence summary
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1589.001 · Credentialsconf 652
- T1593.001 · Social Mediaconf 601
- T1213.002 · Sharepointconf 601evidence: July 2026 CVE Landscape
- T1584.008 · Network Devicesconf 601evidence: July 2026 CVE Landscape
- T1588.006 · Vulnerabilitiesconf 601evidence: July 2026 CVE Landscape
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|