Threat actor · all actors
InceptionG0100 state
🇷🇺 RU
aka Inception, Inception Framework, Cloud Atlas, Clean Ursa, OXYGEN, G0100, ATK116, Blue Odin
Last updated: 2026-08-20
About this actor
[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 34 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1005Data from Local System ↗T1027Obfuscated Files or Information ↗T1027.013Encrypted/Encoded File ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.005Visual Basic ↗T1069Permission Groups Discovery ↗T1069.002Domain Groups ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1090Proxy ↗T1090.003Multi-hop Proxy ↗T1102Web Service ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.005Mshta ↗T1218.010Regsvr32 ↗T1221Template Injection ↗T1518Software Discovery ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1573Encrypted Channel ↗T1573.001Symmetric Cryptography ↗T1588Obtain Capabilities ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 21 / 34 | 62% |
SI-3 | 20 / 34 | 59% |
CA-7 | 18 / 34 | 53% |
CM-6 | 18 / 34 | 53% |
CM-2 | 17 / 34 | 50% |
CM-7 | 15 / 34 | 44% |
SC-7 | 14 / 34 | 41% |
AC-4 | 13 / 34 | 38% |
SI-10 | 11 / 34 | 32% |
SI-7 | 11 / 34 | 32% |
SI-2 | 10 / 34 | 29% |
AC-3 | 9 / 34 | 26% |
AC-6 | 7 / 34 | 21% |
CM-8 | 7 / 34 | 21% |
RA-5 | 7 / 34 | 21% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- Frankenstein 0.38
- Sidewinder 0.36
- Confucius 0.35
- APT19 0.35
- APT33 0.33
Same nation-state
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00