The threat group your red team should emulate is the one that most often attacks your industry, with the same objectives and the same behavior your real attack surface exposes. That single decision, made before any tooling or scoping, is what separates a threat-led red team from a generic penetration test. It also determines whether the final report tells your board how you would hold up against the adversary you will actually face, or against a hypothetical one you will not.
Speed is the reason the choice matters. Adversaries now move from a first compromised host to a second in an average of 48 minutes, and the fastest breakout on record is 51 seconds, per CrowdStrike's 2025 Global Threat Report. Seventy-nine percent of 2024 detections were malware-free, driven by hands-on-keyboard intrusions and valid-credential abuse rather than droppable malware. Meanwhile the global median dwell time sits at 11 days (Mandiant M-Trends 2025). If you only have days to detect and contain, your exercise has to rehearse the specific adversary who will spend those days inside your environment.
This guide gives buyers a sourced, MITRE ATT&CK-mapped answer for ten industries, plus a repeatable method for picking your own adversary. Every row is cited to published threat intelligence so the selection survives scrutiny from a board, an auditor, or a regulator.
The short answer, by industry
The direct answer, before the detail: emulate the adversary whose documented targeting and motivation match your sector. For financial services, that is APT38 and FIN7. For energy and utilities, Sandworm and Volt Typhoon. For technology and SaaS, Scattered Spider and LAPSUS$. For healthcare, Wizard Spider and Scattered Spider. The full mapping, with MITRE ATT&CK group IDs and the intelligence behind each choice, is in the table below.
Key takeaways
Adversary selection is the highest-leverage decision in a red team, and most buyers skip it. A test that emulates a credible, industry-matched group produces defensible findings. A test that emulates a generic "attacker" produces findings you cannot map to real risk.
Financially motivated crews and state-sponsored groups behave differently, and your industry usually faces one more than the other. Retail and hospitality face payment-card crews like FIN6 and FIN7. Critical infrastructure faces state actors like Sandworm and Volt Typhoon that pre-position for disruption (CISA AA24-038A).
Identity is the modern initial-access path across almost every sector. Stolen credentials rose to the second most common infection vector in 2024 at 16 percent (Mandiant M-Trends 2025), and access-broker advertisements selling valid credentials surged 50 percent year over year (CrowdStrike 2025). Groups like Scattered Spider (G1015) built their whole playbook around it.
For regulated testing, adversary selection should come from independent threat intelligence, not from the testers themselves. Frameworks such as DORA, CBEST, and OSFI expect the scenario to reflect real threats to your firm, which is why the intelligence step is separated from the red team step.
How this mapping was built
The mapping draws on named primary threat intelligence: the MITRE ATT&CK Groups knowledge base for documented targeting and technique attribution, joint advisories from CISA and the FBI, the CrowdStrike 2025 Global Threat Report, Mandiant's M-Trends 2025, and the Microsoft Digital Defense Report. Each industry row lists the groups whose published targeting most closely matches that sector, with the ATT&CK group ID so you can trace the behavior yourself. Every group ID links to its MITRE ATT&CK profile.
Two rules kept the list honest. First, a group appears against an industry only where a named source documents targeting of that sector, not where it is merely plausible. Second, group names change constantly across vendors, so the ATT&CK group ID is the anchor. Where a vendor alias is more familiar than the ATT&CK name, the alias is noted. This is a starting point for a scoping conversation, not a substitute for a current intelligence pull against your own firm.
The industry-to-adversary mapping

Industry | Emulate first | ATT&CK group IDs | Motivation | Intelligence basis |
|---|---|---|---|---|
Financial services & banking | G0082, G0046 | State (revenue), eCrime | APT38 targets banks, SWIFT endpoints, ATMs, and crypto exchanges; FIN7 targets financial services (MITRE ATT&CK) | |
Retail & e-commerce | G0037, G0046 | eCrime | FIN6 targets point-of-sale and e-commerce payment data (Magecart Group 6); FIN7 targets retail and restaurants (MITRE ATT&CK) | |
Hospitality & gaming | G1015, G0061 | eCrime | Scattered Spider expanded to gaming and hospitality in 2023; FIN8 targets hospitality POS (MITRE ATT&CK) | |
Healthcare & pharma | G0102, G1015 | eCrime (ransomware) | Wizard Spider ran Ryuk and Conti against hospitals; Scattered Spider hits healthcare (MITRE ATT&CK, CISA AA23-320A) | |
Technology & SaaS | G1015, G1004, G0016 | eCrime, state (espionage) | Scattered Spider abuses identity and help desks; LAPSUS$ extorts source code; APT29 targets cloud and Microsoft 365 (MITRE ATT&CK) | |
Energy, utilities & OT | G0034, G1017, G0064 | State (disruption) | Sandworm targets electric grids; Volt Typhoon pre-positions in US critical infrastructure; APT33 targets energy (MITRE ATT&CK, CISA AA24-038A) | |
Government & defense | G0016, G0007, G0034 | State (espionage, disruption) | APT29 (SVR) and APT28 (GRU) target government, military, and defense; Sandworm targets government (MITRE ATT&CK) | |
Manufacturing & industrial | G0096, G1004 | State plus eCrime, extortion | APT41 blends espionage and financial motives across manufacturing and tech; LAPSUS$ targets manufacturing (MITRE ATT&CK) | |
Telecommunications | G1017, G0096 | State | Volt Typhoon targets telecom and critical infrastructure; APT41 targets telecom (MITRE ATT&CK, CISA AA24-038A) | |
Professional services & MSP | G1015, G0016 | eCrime, state | Scattered Spider targets business process outsourcing and MSPs; APT29 uses supply-chain access (MITRE ATT&CK) |
Group IDs link to their MITRE ATT&CK profiles. Aliases in wide use: Scattered Spider is also Octo Tempest and UNC3944; APT29 is also Cozy Bear and Midnight Blizzard; Sandworm is also APT44 and Seashell Blizzard; Wizard Spider overlaps with the FIN12 label.
Why threat-led emulation beats a generic test
A generic penetration test asks whether vulnerabilities exist. A threat-led red team asks whether a specific adversary could reach your crown jewels the way that adversary actually operates. The difference shows up in what gets rehearsed.
Consider identity. Across sectors, the modern break-in is a login, not an exploit. Valid-account abuse was the leading initial-access method for 35 percent of cloud incidents in the first half of 2024, and access-broker listings for stolen credentials rose 50 percent year over year (CrowdStrike 2025 Global Threat Report). A red team emulating Scattered Spider will rehearse help-desk social engineering and identity-provider abuse because that is the group's signature. A generic test that spends its hours on network scanning will miss the exact path your real adversary would take. For a deeper treatment of picking the right partner for this work, see our guide on how to choose a threat-led penetration testing provider.
Motivation matters as much as technique. A ransomware crew like Wizard Spider optimizes for encryption and extortion leverage against hospitals, while a state group like Volt Typhoon optimizes for quiet, long-term pre-positioning inside critical infrastructure (CISA AA24-038A). Emulating the wrong one wastes the engagement. The chart below groups the adversaries in this guide by motivation and origin so you can see which archetype fits your risk.

How to pick your adversary in five steps
Selection is a short, structured decision. You do not need to model every group that has ever touched your sector, and you should not. One to three well-chosen adversaries produce a focused, defensible exercise.

Define the crown jewels first. Decide what a win looks like for the attacker: patient records, payment rails, source code, a control system. The objective drives the adversary, not the reverse. Our note on red team objectives and crown-jewel scoping covers how to frame this.
Pull current industry threat intelligence. Start with the mapping above, then refresh it against the latest MITRE ATT&CK updates, CISA advisories, and vendor threat reports. Targeting shifts; a group that ignored your sector two years ago may lead it today.
Shortlist one to three groups. Prefer the adversary whose documented objectives match your crown jewels and whose behavior your controls are least ready for. Breadth dilutes; depth against a credible group is the goal.
Map the group to ATT&CK behavior at the right altitude. Translate the shortlisted group into the tactics and techniques it is known for, so blue team detections can be measured against a named baseline rather than a vague notion of "an attacker."
Scope the emulation and the rules of engagement. Set objectives, guardrails, and success criteria before execution. For regulated tests, this is also where the independent-intelligence requirement is satisfied.
What adversary emulation looks like at Stingrai
Stingrai runs intelligence-led red teaming where a real adversary is selected first, then emulated by senior human operators, then reported against MITRE ATT&CK so your blue team can measure detection and response tactic by tactic. Human red teamers own the emulation end to end, from identity-led initial access through to the objective, because credible adversary behavior requires human judgment, not automation.
Our AI web-application agent, Snipe, works a different and complementary problem. Snipe hunts complex, high-impact vulnerabilities in web applications, the IDOR, broken-authorization, and business-logic flaws that generic scanners miss, and it can run as a pull-request gating check. That web-application depth strengthens the application layer an adversary would target, and you can read more about it on our web application penetration testing page. The red team decides which adversary to become; Snipe hardens the app surface that adversary would probe.
For regulated firms, the adversary is not chosen by the people executing the test. Under threat-led frameworks such as DORA, CBEST, and OSFI intelligence-led testing, the scenario is built from an independent threat-intelligence provider so the exercise reflects the real threats to your firm. Stingrai's penetration testing and red teaming produce ATT&CK-mapped evidence that supports those programs. Our overview of DORA threat-led penetration testing walks through how the intelligence and testing phases fit together.

What this means for defenders
Choose one to three industry-matched adversaries, then go deep. A focused emulation of APT38 or Scattered Spider teaches you more than a shallow test against a generic attacker profile.
Rehearse identity first. With stolen credentials now the second-ranked infection vector and valid-account abuse leading cloud incidents, your exercise should assume the adversary logs in rather than breaks in.
Measure detection against named ATT&CK behavior. Tactic-by-tactic scoring against a specific group turns a red team into a metric your board and your blue team can track over time.
Refresh the adversary each cycle. Targeting changes. A continuous or recurring testing model keeps the emulated adversary current instead of frozen at last year's threat picture.
Separate intelligence from execution for regulated tests. If DORA, CBEST, or OSFI apply, source the adversary from an independent intelligence provider so the scenario, and the evidence it produces, holds up.
Ready to scope a threat-led red team against the adversary that actually targets your industry? Review Stingrai's red teaming service or see current engagement options on our pricing page.
Frequently asked questions
Which real-world threat group should my red team emulate for my industry?
Emulate the group whose documented targeting and motivation match your sector and crown jewels. Financial services should start with APT38 (G0082) and FIN7 (G0046); technology and SaaS with Scattered Spider (G1015) and LAPSUS$ (G1004); energy and utilities with Sandworm (G0034) and Volt Typhoon (G1017); healthcare with Wizard Spider (G0102). The full industry table above cites each choice to MITRE ATT&CK and CISA.
What is adversary emulation in a red team?
Adversary emulation is a red team exercise built around a specific, named threat group, so the test rehearses that group's objectives and known behavior rather than a generic attacker. The behavior is typically expressed in MITRE ATT&CK tactics and techniques so the blue team can measure detection against a documented baseline.
How is threat-led red teaming different from a penetration test?
A penetration test asks whether exploitable vulnerabilities exist across a defined scope. Threat-led red teaming asks whether a specific adversary could achieve a defined objective, such as reaching payment rails or a control system, using the way that adversary actually operates. The two are complementary; the red team is scenario-driven and objective-based.
Should I emulate financially motivated groups or state-sponsored groups?
It depends on your industry and what an attacker would want from you. Retail, hospitality, and healthcare most often face financially motivated crews and ransomware operators like FIN6, FIN7, and Wizard Spider. Critical infrastructure, government, and telecom face state-sponsored groups like Sandworm, Volt Typhoon, and APT29. Several firms should model both.
What are MITRE ATT&CK group IDs and why do they matter?
MITRE ATT&CK assigns each tracked threat group a stable identifier, such as G0046 for FIN7, along with documented targeting and techniques. Because vendors use different names for the same group, the ATT&CK group ID is the reliable anchor for scoping an emulation and for mapping detections. You can browse them in the MITRE ATT&CK Groups knowledge base.
How many threat groups should a single red team emulate?
Usually one to three. A focused emulation of a well-matched adversary produces deeper, more defensible findings than a shallow sweep across many groups. The right number depends on your crown jewels and the distinct archetypes that threaten them, for example one ransomware crew and one state actor.
Does adversary emulation support DORA, CBEST, or OSFI testing?
Yes. Threat-led frameworks such as DORA, CBEST, and OSFI intelligence-led testing expect the scenario to reflect real threats to your firm, with adversary selection sourced from independent threat intelligence. Red teaming and penetration testing produce ATT&CK-mapped evidence that supports those programs.
Where can I get current threat intelligence to choose an adversary?
Start with the MITRE ATT&CK Groups knowledge base, then layer in joint CISA and FBI advisories, the CrowdStrike Global Threat Report, Mandiant M-Trends, and the Microsoft Digital Defense Report. Refresh the picture each testing cycle, because targeting by sector shifts from year to year.
References
MITRE. ATT&CK Groups Knowledge Base. https://attack.mitre.org/groups/. Documented threat-group targeting, techniques, and stable group identifiers used throughout this mapping.
MITRE. FIN7 (G0046). https://attack.mitre.org/groups/G0046/. Financially motivated group targeting retail, hospitality, and financial services.
MITRE. APT38 (G0082). https://attack.mitre.org/groups/G0082/. North Korean group targeting banks, SWIFT endpoints, ATMs, and cryptocurrency exchanges.
MITRE. FIN6 (G0037). https://attack.mitre.org/groups/G0037/. Payment-card group targeting point-of-sale and e-commerce, also tracked as Magecart Group 6.
MITRE. Scattered Spider (G1015). https://attack.mitre.org/groups/G1015/. Identity-focused eCrime group targeting technology, telecom, gaming, hospitality, and retail.
MITRE. Wizard Spider (G0102). https://attack.mitre.org/groups/G0102/. Ransomware operator behind Ryuk and Conti, with documented targeting of hospitals.
MITRE. Sandworm Team (G0034). https://attack.mitre.org/groups/G0034/. Russian GRU group targeting electric-power and other critical infrastructure.
MITRE. Volt Typhoon (G1017). https://attack.mitre.org/groups/G1017/. Chinese state group pre-positioning in US critical infrastructure and telecom.
MITRE. APT29 (G0016), APT28 (G0007), APT33 (G0064), APT41 (G0096), FIN8 (G0061), LAPSUS$ (G1004). https://attack.mitre.org/groups/. Additional groups referenced in the industry mapping.
CISA and FBI. Scattered Spider (AA23-320A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a. Joint advisory on Scattered Spider tradecraft and targeted sectors.
CISA. PRC State-Sponsored Actors Compromise US Critical Infrastructure (AA24-038A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a. Advisory on Volt Typhoon pre-positioning in critical infrastructure.
CrowdStrike. 2025 Global Threat Report. https://www.crowdstrike.com/en-us/blog/crowdstrike-2025-global-threat-report-findings/. Breakout time, malware-free intrusions, and access-broker trends.
Mandiant (Google Cloud). M-Trends 2025. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2025/. Global median dwell time and initial infection vectors.



