Cyber Resilience

Threat actor · all actors

GCMANG0036 state

🇷🇺 RU

aka GCMAN, G0036

Last updated: 2026-08-20

0attributed CVEs
3ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[GCMAN](https://attack.mitre.org/groups/G0036) is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services. (Citation: Securelist GCMAN)

Source: MITRE ATT&CK

Names & naming systems

Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.

MITRE ATT&CKG-number catalogue id

G0036

Unclassifiedno scheme matched

GCMAN

How we know this

Data origin
MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
Techniques
MITRE ATT&CK STIX mappings — 3 ATT&CK techniques on file.
Named victims
None on file.

Thin data: Only 3 ATT&CK techniques mapped — a thin behavioural profile; absence is not evidence of a narrow toolkit.

See how actor data is built for the full pipeline.

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
AC-173 / 3100%
AC-23 / 3100%
AC-33 / 3100%
AC-63 / 3100%
CM-23 / 3100%
CM-53 / 3100%
CM-63 / 3100%
IA-23 / 3100%
SI-43 / 3100%
AC-202 / 367%
AC-52 / 367%
AC-72 / 367%
CM-72 / 367%
CM-82 / 367%
IA-52 / 367%

Co-occurring actors

None.

Similar actors

Similar TTPs