main logo icon

Published on

July 8, 2026

|

11 min read

Which Threat Group Should Your Red Team Emulate? A Buyer Guide by Industry

A sourced buyer guide to picking the right real-world adversary for your red team to emulate, mapped by industry to MITRE ATT&CK groups and published threat intelligence.

Arafat Afzalzada

Arafat Afzalzada

Founder

AdvisoriesSocial Engineering

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The threat group your red team should emulate is the one that most often attacks your industry, with the same goals and behavior your real risk exposes. - Financial services and banking: emulate APT38 (G0082) and FIN7 (G0046). - Retail and e-commerce: emulate FIN6 (G0037) and FIN7 (G0046). - Healthcare and pharma: emulate Wizard Spider (G0102) and Scattered Spider (G1015). - Technology and SaaS: emulate Scattered Spider (G1015), LAPSUS$ (G1004), and APT29 (G0016). - Energy, utilities, and OT: emulate Sandworm (G0034), Volt Typhoon (G1017), and APT33 (G0064). - Adversaries move host to host in an average of 48 minutes, fastest 51 seconds (CrowdStrike 2025 Global Threat Report). - Every mapping row below is cited to MITRE ATT&CK, CISA, CrowdStrike, or Mandiant so any selection can be defended to a board or a regulator.

The threat group your red team should emulate is the one that most often attacks your industry, with the same objectives and the same behavior your real attack surface exposes. That single decision, made before any tooling or scoping, is what separates a threat-led red team from a generic penetration test. It also determines whether the final report tells your board how you would hold up against the adversary you will actually face, or against a hypothetical one you will not.

Speed is the reason the choice matters. Adversaries now move from a first compromised host to a second in an average of 48 minutes, and the fastest breakout on record is 51 seconds, per CrowdStrike's 2025 Global Threat Report. Seventy-nine percent of 2024 detections were malware-free, driven by hands-on-keyboard intrusions and valid-credential abuse rather than droppable malware. Meanwhile the global median dwell time sits at 11 days (Mandiant M-Trends 2025). If you only have days to detect and contain, your exercise has to rehearse the specific adversary who will spend those days inside your environment.

This guide gives buyers a sourced, MITRE ATT&CK-mapped answer for ten industries, plus a repeatable method for picking your own adversary. Every row is cited to published threat intelligence so the selection survives scrutiny from a board, an auditor, or a regulator.

The short answer, by industry

The direct answer, before the detail: emulate the adversary whose documented targeting and motivation match your sector. For financial services, that is APT38 and FIN7. For energy and utilities, Sandworm and Volt Typhoon. For technology and SaaS, Scattered Spider and LAPSUS$. For healthcare, Wizard Spider and Scattered Spider. The full mapping, with MITRE ATT&CK group IDs and the intelligence behind each choice, is in the table below.

Key takeaways

  • Adversary selection is the highest-leverage decision in a red team, and most buyers skip it. A test that emulates a credible, industry-matched group produces defensible findings. A test that emulates a generic "attacker" produces findings you cannot map to real risk.

  • Financially motivated crews and state-sponsored groups behave differently, and your industry usually faces one more than the other. Retail and hospitality face payment-card crews like FIN6 and FIN7. Critical infrastructure faces state actors like Sandworm and Volt Typhoon that pre-position for disruption (CISA AA24-038A).

  • Identity is the modern initial-access path across almost every sector. Stolen credentials rose to the second most common infection vector in 2024 at 16 percent (Mandiant M-Trends 2025), and access-broker advertisements selling valid credentials surged 50 percent year over year (CrowdStrike 2025). Groups like Scattered Spider (G1015) built their whole playbook around it.

  • For regulated testing, adversary selection should come from independent threat intelligence, not from the testers themselves. Frameworks such as DORA, CBEST, and OSFI expect the scenario to reflect real threats to your firm, which is why the intelligence step is separated from the red team step.

How this mapping was built

The mapping draws on named primary threat intelligence: the MITRE ATT&CK Groups knowledge base for documented targeting and technique attribution, joint advisories from CISA and the FBI, the CrowdStrike 2025 Global Threat Report, Mandiant's M-Trends 2025, and the Microsoft Digital Defense Report. Each industry row lists the groups whose published targeting most closely matches that sector, with the ATT&CK group ID so you can trace the behavior yourself. Every group ID links to its MITRE ATT&CK profile.

Two rules kept the list honest. First, a group appears against an industry only where a named source documents targeting of that sector, not where it is merely plausible. Second, group names change constantly across vendors, so the ATT&CK group ID is the anchor. Where a vendor alias is more familiar than the ATT&CK name, the alias is noted. This is a starting point for a scoping conversation, not a substitute for a current intelligence pull against your own firm.

The industry-to-adversary mapping

Threat Group Emulation Mapping Matrix

Industry

Emulate first

ATT&CK group IDs

Motivation

Intelligence basis

Financial services & banking

APT38, FIN7

G0082, G0046

State (revenue), eCrime

APT38 targets banks, SWIFT endpoints, ATMs, and crypto exchanges; FIN7 targets financial services (MITRE ATT&CK)

Retail & e-commerce

FIN6, FIN7

G0037, G0046

eCrime

FIN6 targets point-of-sale and e-commerce payment data (Magecart Group 6); FIN7 targets retail and restaurants (MITRE ATT&CK)

Hospitality & gaming

Scattered Spider, FIN8

G1015, G0061

eCrime

Scattered Spider expanded to gaming and hospitality in 2023; FIN8 targets hospitality POS (MITRE ATT&CK)

Healthcare & pharma

Wizard Spider, Scattered Spider

G0102, G1015

eCrime (ransomware)

Wizard Spider ran Ryuk and Conti against hospitals; Scattered Spider hits healthcare (MITRE ATT&CK, CISA AA23-320A)

Technology & SaaS

Scattered Spider, LAPSUS$, APT29

G1015, G1004, G0016

eCrime, state (espionage)

Scattered Spider abuses identity and help desks; LAPSUS$ extorts source code; APT29 targets cloud and Microsoft 365 (MITRE ATT&CK)

Energy, utilities & OT

Sandworm, Volt Typhoon, APT33

G0034, G1017, G0064

State (disruption)

Sandworm targets electric grids; Volt Typhoon pre-positions in US critical infrastructure; APT33 targets energy (MITRE ATT&CK, CISA AA24-038A)

Government & defense

APT29, APT28, Sandworm

G0016, G0007, G0034

State (espionage, disruption)

APT29 (SVR) and APT28 (GRU) target government, military, and defense; Sandworm targets government (MITRE ATT&CK)

Manufacturing & industrial

APT41, LAPSUS$

G0096, G1004

State plus eCrime, extortion

APT41 blends espionage and financial motives across manufacturing and tech; LAPSUS$ targets manufacturing (MITRE ATT&CK)

Telecommunications

Volt Typhoon, APT41

G1017, G0096

State

Volt Typhoon targets telecom and critical infrastructure; APT41 targets telecom (MITRE ATT&CK, CISA AA24-038A)

Professional services & MSP

Scattered Spider, APT29

G1015, G0016

eCrime, state

Scattered Spider targets business process outsourcing and MSPs; APT29 uses supply-chain access (MITRE ATT&CK)

Group IDs link to their MITRE ATT&CK profiles. Aliases in wide use: Scattered Spider is also Octo Tempest and UNC3944; APT29 is also Cozy Bear and Midnight Blizzard; Sandworm is also APT44 and Seashell Blizzard; Wizard Spider overlaps with the FIN12 label.

Why threat-led emulation beats a generic test

A generic penetration test asks whether vulnerabilities exist. A threat-led red team asks whether a specific adversary could reach your crown jewels the way that adversary actually operates. The difference shows up in what gets rehearsed.

Consider identity. Across sectors, the modern break-in is a login, not an exploit. Valid-account abuse was the leading initial-access method for 35 percent of cloud incidents in the first half of 2024, and access-broker listings for stolen credentials rose 50 percent year over year (CrowdStrike 2025 Global Threat Report). A red team emulating Scattered Spider will rehearse help-desk social engineering and identity-provider abuse because that is the group's signature. A generic test that spends its hours on network scanning will miss the exact path your real adversary would take. For a deeper treatment of picking the right partner for this work, see our guide on how to choose a threat-led penetration testing provider.

Motivation matters as much as technique. A ransomware crew like Wizard Spider optimizes for encryption and extortion leverage against hospitals, while a state group like Volt Typhoon optimizes for quiet, long-term pre-positioning inside critical infrastructure (CISA AA24-038A). Emulating the wrong one wastes the engagement. The chart below groups the adversaries in this guide by motivation and origin so you can see which archetype fits your risk.

Threat Group Emulation Motivation Map

How to pick your adversary in five steps

Selection is a short, structured decision. You do not need to model every group that has ever touched your sector, and you should not. One to three well-chosen adversaries produce a focused, defensible exercise.

Threat Group Emulation Selection Funnel
  1. Define the crown jewels first. Decide what a win looks like for the attacker: patient records, payment rails, source code, a control system. The objective drives the adversary, not the reverse. Our note on red team objectives and crown-jewel scoping covers how to frame this.

  2. Pull current industry threat intelligence. Start with the mapping above, then refresh it against the latest MITRE ATT&CK updates, CISA advisories, and vendor threat reports. Targeting shifts; a group that ignored your sector two years ago may lead it today.

  3. Shortlist one to three groups. Prefer the adversary whose documented objectives match your crown jewels and whose behavior your controls are least ready for. Breadth dilutes; depth against a credible group is the goal.

  4. Map the group to ATT&CK behavior at the right altitude. Translate the shortlisted group into the tactics and techniques it is known for, so blue team detections can be measured against a named baseline rather than a vague notion of "an attacker."

  5. Scope the emulation and the rules of engagement. Set objectives, guardrails, and success criteria before execution. For regulated tests, this is also where the independent-intelligence requirement is satisfied.

What adversary emulation looks like at Stingrai

Stingrai runs intelligence-led red teaming where a real adversary is selected first, then emulated by senior human operators, then reported against MITRE ATT&CK so your blue team can measure detection and response tactic by tactic. Human red teamers own the emulation end to end, from identity-led initial access through to the objective, because credible adversary behavior requires human judgment, not automation.

Our AI web-application agent, Snipe, works a different and complementary problem. Snipe hunts complex, high-impact vulnerabilities in web applications, the IDOR, broken-authorization, and business-logic flaws that generic scanners miss, and it can run as a pull-request gating check. That web-application depth strengthens the application layer an adversary would target, and you can read more about it on our web application penetration testing page. The red team decides which adversary to become; Snipe hardens the app surface that adversary would probe.

For regulated firms, the adversary is not chosen by the people executing the test. Under threat-led frameworks such as DORA, CBEST, and OSFI intelligence-led testing, the scenario is built from an independent threat-intelligence provider so the exercise reflects the real threats to your firm. Stingrai's penetration testing and red teaming produce ATT&CK-mapped evidence that supports those programs. Our overview of DORA threat-led penetration testing walks through how the intelligence and testing phases fit together.

Threat Group Emulation Tlpt Evidence

What this means for defenders

  • Choose one to three industry-matched adversaries, then go deep. A focused emulation of APT38 or Scattered Spider teaches you more than a shallow test against a generic attacker profile.

  • Rehearse identity first. With stolen credentials now the second-ranked infection vector and valid-account abuse leading cloud incidents, your exercise should assume the adversary logs in rather than breaks in.

  • Measure detection against named ATT&CK behavior. Tactic-by-tactic scoring against a specific group turns a red team into a metric your board and your blue team can track over time.

  • Refresh the adversary each cycle. Targeting changes. A continuous or recurring testing model keeps the emulated adversary current instead of frozen at last year's threat picture.

  • Separate intelligence from execution for regulated tests. If DORA, CBEST, or OSFI apply, source the adversary from an independent intelligence provider so the scenario, and the evidence it produces, holds up.

Ready to scope a threat-led red team against the adversary that actually targets your industry? Review Stingrai's red teaming service or see current engagement options on our pricing page.

Frequently asked questions

Which real-world threat group should my red team emulate for my industry?

Emulate the group whose documented targeting and motivation match your sector and crown jewels. Financial services should start with APT38 (G0082) and FIN7 (G0046); technology and SaaS with Scattered Spider (G1015) and LAPSUS$ (G1004); energy and utilities with Sandworm (G0034) and Volt Typhoon (G1017); healthcare with Wizard Spider (G0102). The full industry table above cites each choice to MITRE ATT&CK and CISA.

What is adversary emulation in a red team?

Adversary emulation is a red team exercise built around a specific, named threat group, so the test rehearses that group's objectives and known behavior rather than a generic attacker. The behavior is typically expressed in MITRE ATT&CK tactics and techniques so the blue team can measure detection against a documented baseline.

How is threat-led red teaming different from a penetration test?

A penetration test asks whether exploitable vulnerabilities exist across a defined scope. Threat-led red teaming asks whether a specific adversary could achieve a defined objective, such as reaching payment rails or a control system, using the way that adversary actually operates. The two are complementary; the red team is scenario-driven and objective-based.

Should I emulate financially motivated groups or state-sponsored groups?

It depends on your industry and what an attacker would want from you. Retail, hospitality, and healthcare most often face financially motivated crews and ransomware operators like FIN6, FIN7, and Wizard Spider. Critical infrastructure, government, and telecom face state-sponsored groups like Sandworm, Volt Typhoon, and APT29. Several firms should model both.

What are MITRE ATT&CK group IDs and why do they matter?

MITRE ATT&CK assigns each tracked threat group a stable identifier, such as G0046 for FIN7, along with documented targeting and techniques. Because vendors use different names for the same group, the ATT&CK group ID is the reliable anchor for scoping an emulation and for mapping detections. You can browse them in the MITRE ATT&CK Groups knowledge base.

How many threat groups should a single red team emulate?

Usually one to three. A focused emulation of a well-matched adversary produces deeper, more defensible findings than a shallow sweep across many groups. The right number depends on your crown jewels and the distinct archetypes that threaten them, for example one ransomware crew and one state actor.

Does adversary emulation support DORA, CBEST, or OSFI testing?

Yes. Threat-led frameworks such as DORA, CBEST, and OSFI intelligence-led testing expect the scenario to reflect real threats to your firm, with adversary selection sourced from independent threat intelligence. Red teaming and penetration testing produce ATT&CK-mapped evidence that supports those programs.

Where can I get current threat intelligence to choose an adversary?

Start with the MITRE ATT&CK Groups knowledge base, then layer in joint CISA and FBI advisories, the CrowdStrike Global Threat Report, Mandiant M-Trends, and the Microsoft Digital Defense Report. Refresh the picture each testing cycle, because targeting by sector shifts from year to year.

References

  1. MITRE. ATT&CK Groups Knowledge Base. https://attack.mitre.org/groups/. Documented threat-group targeting, techniques, and stable group identifiers used throughout this mapping.

  2. MITRE. FIN7 (G0046). https://attack.mitre.org/groups/G0046/. Financially motivated group targeting retail, hospitality, and financial services.

  3. MITRE. APT38 (G0082). https://attack.mitre.org/groups/G0082/. North Korean group targeting banks, SWIFT endpoints, ATMs, and cryptocurrency exchanges.

  4. MITRE. FIN6 (G0037). https://attack.mitre.org/groups/G0037/. Payment-card group targeting point-of-sale and e-commerce, also tracked as Magecart Group 6.

  5. MITRE. Scattered Spider (G1015). https://attack.mitre.org/groups/G1015/. Identity-focused eCrime group targeting technology, telecom, gaming, hospitality, and retail.

  6. MITRE. Wizard Spider (G0102). https://attack.mitre.org/groups/G0102/. Ransomware operator behind Ryuk and Conti, with documented targeting of hospitals.

  7. MITRE. Sandworm Team (G0034). https://attack.mitre.org/groups/G0034/. Russian GRU group targeting electric-power and other critical infrastructure.

  8. MITRE. Volt Typhoon (G1017). https://attack.mitre.org/groups/G1017/. Chinese state group pre-positioning in US critical infrastructure and telecom.

  9. MITRE. APT29 (G0016), APT28 (G0007), APT33 (G0064), APT41 (G0096), FIN8 (G0061), LAPSUS$ (G1004). https://attack.mitre.org/groups/. Additional groups referenced in the industry mapping.

  10. CISA and FBI. Scattered Spider (AA23-320A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a. Joint advisory on Scattered Spider tradecraft and targeted sectors.

  11. CISA. PRC State-Sponsored Actors Compromise US Critical Infrastructure (AA24-038A). https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a. Advisory on Volt Typhoon pre-positioning in critical infrastructure.

  12. CrowdStrike. 2025 Global Threat Report. https://www.crowdstrike.com/en-us/blog/crowdstrike-2025-global-threat-report-findings/. Breakout time, malware-free intrusions, and access-broker trends.

  13. Mandiant (Google Cloud). M-Trends 2025. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2025/. Global median dwell time and initial infection vectors.

0 views

0

X

Related reading

Scattered Spider Identity Takeover: A Buyer's Guide to Account Recovery Red Teaming
Social EngineeringAdvisories

Scattered Spider Identity Takeover: A Buyer's Guide to Account Recovery Red Teaming

How to buy a red team that tests your account-recovery and help-desk workflows against Scattered Spider social engineering, plus a resilience checklist.

11 min read

Password Statistics 2026: Breaches, Credential Stuffing, and Passkey Adoption
Network SecurityWeb App Security

Password Statistics 2026: Breaches, Credential Stuffing, and Passkey Adoption

6B malware-stolen passwords surfaced in 2025 (Specops) and 22% of breaches start with stolen credentials (Verizon). Every 2026 password statistic is sourced.

25 min read

Top Industries Targeted by Hackers 2026: Manufacturing, Healthcare, and Finance
Network SecurityWeb App Security

Top Industries Targeted by Hackers 2026: Manufacturing, Healthcare, and Finance

Manufacturing held #1 for the 4th year (IBM X-Force, 26%). Healthcare leads breach cost at US$7.42M (IBM 2025). Verified industry-targeting stats.

26 min read

Contents

X