Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 14:51:48 UTC Home > List all groups > List all tools > List all groups using tool Havij Tool: Havij Names Havij Category Tools Type Info stealer, Exfiltration Description (Check Point) Havij, an automatic SQL Injection tool, is distributed by ITSecTeam, an Iranian security company. The name Havij means “carrot”, which is the tool’s icon. The tool is designed with a user-friendly GUI that makes it easy for an operator to retrieve the desired data. Such ease of use may be the reason behind the transition from attacks deployed by code-writing hackers to those by non-technical users. Information MITRE ATT&CK AlienVault OTX Last change to this tool card: 08 May 2020 Download this tool card in JSON format All groups using tool Havij Changed Name Country Observed APT groups Magic Hound, APT 35, Cobalt Illusion, Charming Kitten 2012-Jun 2025 1 group listed (1 APT, 0 other, 0 unknown) https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=76ac3306-33c5-44b6-b5da-4dcb7d7930a9 Page 1 of 2 Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=76ac3306-33c5-44b6-b5da-4dcb7d7930a9 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=76ac3306-33c5-44b6-b5da-4dcb7d7930a9 Page 2 of 2