not MITRE’s ATT&CK Group
CostaRicto
How MITRE ATT&CK characterizes this group1: CostaRicto is a suspected hacker-for-hire cyber espionage campaign that has targeted multiple industries worldwide since at least 2019. CostaRicto's targets, a large portion of which are financial institutions, are scattered across Europe, the Americas, Asia, Australia, and Africa, with a large concentration in South Asia.
Origin / sponsor: not established from a curated public advisory — see Coverage & confidence. Not asserted here.
Read as a state-directed operator, not a smash-and-grab.
A nation-state classification means patience, tradecraft, and an intelligence objective. When this name attaches to a vulnerability, the question shifts from “will someone exploit it” to “has a well-resourced service already built it into an operation.” All tradecraft below is sourced to MITRE ATT&CK.
Known for
— signature moves, each sourced to ATT&CKTradecraft heatmap
— ATT&CK techniques mapped onto the five attacker-outcome narrativesNo techniques are recorded for this group in the ATT&CK snapshot below — the tradecraft heatmap is empty. That is an honest coverage gap (sparse / legacy / revoked group), never a claim that the actor does nothing.1
Arsenal
— named tools & malware ATT&CK attributes to this groupATT&CK attributes no software to G0132 at this snapshot. Absence is a finding, not a claim of harmlessness.
Campaign highlights
— attributed operations in the ATT&CK recordNo attributed campaigns — coverage gap
Latest activity
— with explicit confidence, and what we cannot yet claimsnapshot
The most recent cited activity in this card is the ATT&CK record itself. We do not paste a “last seen this week” line we cannot source. Recency from secondary reporting appears here only when attached to a named advisory.