C0028
2015 Ukraine Electric Power Attack
2015 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used BlackEnergy (specifically BlackEnergy3) and KillDisk to target and disrupt transmission and d
2015-12-01 17 techniques ๐Ÿ‡ท๐Ÿ‡บ Sandworm Team
C0025
2016 Ukraine Electric Power Attack
2016 Ukraine Electric Power Attack was a Sandworm Team campaign during which they used Industroyer malware to target and disrupt distribution substations within the Ukrainian power
2016-12-01 21 techniques ๐Ÿ‡ท๐Ÿ‡บ Sandworm Team
C0034
2022 Ukraine Electric Power Attack
The 2022 Ukraine Electric Power Attack was a Sandworm Team campaign that used a combination of GOGETTER, Neo-REGEORG, CaddyWiper, and living of the land (LotL) techniques to gain a
2022-06-01 10 techniques ๐Ÿ‡ท๐Ÿ‡บ Sandworm Team
C0063
2025 Poland Wiper Attacks
2025 Poland Wiper Attacks is a Russian state-sponsored campaign that conducted destructive cyberattacks against Polish energy infrastructure in December 2025. Targets included more
2025-03-01 53 techniques
C0057
3CX Supply Chain Attack
The 3CX Supply Chain Attack was the first publicly reported case of one supply chain compromise triggering another, leading to a cascading, two-stage intrusion. The initial supply
2022-11-01 22 techniques ๐Ÿ‡ฐ๐Ÿ‡ต AppleJeus
C0051
APT28 Nearest Neighbor Campaign
APT28 Nearest Neighbor Campaign was conducted by APT28 from early February 2022 to November 2024 against organizations and individuals with expertise on Ukraine. APT28 primarily le
2022-02-01 18 techniques ๐Ÿ‡ท๐Ÿ‡บ APT28
C0040
APT41 DUST
APT41 DUST was conducted by APT41 from 2023 to July 2024 against entities in Europe, Asia, and the Middle East. APT41 DUST targeted sectors such as shipping, logistics, and media f
2023-01-31 23 techniques ๐Ÿ‡จ๐Ÿ‡ณ APT41
C0062
Anthropic AI-orchestrated Campaign
The Anthropic AI-orchestrated Campaign was conducted in September 2025 by a likely China nexus espionage actor identified as GTG-1002. The Anthropic AI-orchestrated Campaign was a
2025-09-01 26 techniques
C0046
ArcaneDoor
ArcaneDoor is a campaign targeting networking devices from Cisco and other vendors between July 2023 and April 2024, primarily focused on government and critical infrastructure net
2023-07-01 25 techniques
C0010
C0010
C0010 was a cyber espionage campaign conducted by UNC3890 that targeted Israeli shipping, government, aviation, energy, and healthcare organizations. Security researcher assess UNC
2020-12-01 9 techniques
C0011
C0011
C0011 was a suspected cyber espionage campaign conducted by Transparent Tribe that targeted students at universities and colleges in India. Security researchers noted this campaign
2021-12-01 8 techniques ๐Ÿ‡ต๐Ÿ‡ฐ Transparent Tribe
C0015
C0015
C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers ass
2021-08-01 34 techniques
C0017
C0017
C0017 was an APT41 campaign conducted between May 2021 and February 2022 that successfully compromised at least six U.S. state government networks through the exploitation of vulne
2021-05-01 29 techniques ๐Ÿ‡จ๐Ÿ‡ณ APT41
C0018
C0018
C0018 was a month-long ransomware intrusion that successfully deployed AvosLocker onto a compromised network. The unidentified actors gained initial access to the victim network th
2022-02-01 19 techniques
C0021
C0021
C0021 was a spearphishing campaign conducted in November 2018 that targeted public sector institutions, non-governmental organizations (NGOs), educational institutions, and private
2018-11-01 15 techniques
C0026
C0026
C0026 was a campaign identified in September 2022 that included the selective distribution of KOPILUWAK and QUIETCANARY malware to previous ANDROMEDA malware victims in Ukraine thr
2022-08-01 6 techniques
C0027
C0027
C0027 was a financially-motivated campaign linked to Scattered Spider that targeted telecommunications and business process outsourcing (BPO) companies from at least June through D
2022-06-01 28 techniques ๐ŸŒ Scattered Spider
C0032
C0032
C0032 was an extended campaign suspected to involve the Triton adversaries with related capabilities and techniques focused on gaining a foothold within IT environments. This campa
2014-10-01 17 techniques ๐Ÿ‡ท๐Ÿ‡บ TEMP.Veles
C0033
C0033
C0033 was a PROMETHIUM campaign during which they used StrongPity to target Android users. C0033 was the first publicly documented mobile campaign for PROMETHIUM, who previously us
2016-05-01 0 techniques ๐Ÿ‡น๐Ÿ‡ท PROMETHIUM
C0004
CostaRicto
CostaRicto was a suspected hacker-for-hire cyber espionage campaign that targeted multiple industries worldwide, with a large number being financial institutions. CostaRicto actors
2019-10-01 10 techniques
C0029
Cutting Edge
Cutting Edge was a campaign conducted by suspected China-nexus espionage actors, variously identified as UNC5221/UTA0178 and UNC5325, that began as early as December 2023 with the
2023-12-01 31 techniques
C0053
FLORAHOX Activity
FLORAHOX Activity is conducted using a hybrid operational relay box (ORB) network, which combines two types of infrastructure: compromised devices and leased Virtual Private Server
2019-01-01 6 techniques
C0001
Frankenstein
Frankenstein was described by security researchers as a highly-targeted campaign conducted by moderately sophisticated and highly resourceful threat actors in early 2019. The unide
2019-01-01 27 techniques
C0041
FrostyGoop Incident
FrostyGoop Incident took place in January 2024 against a municipal district heating company in Ukraine. Following initial access via likely exploitation of external facing services
2024-01-01 5 techniques
C0007
FunnyDream
FunnyDream was a suspected Chinese cyber espionage campaign that targeted government and foreign organizations in Malaysia, the Philippines, Taiwan, Vietnam, and other parts of Sou
2018-07-01 14 techniques
C0038
HomeLand Justice
HomeLand Justice was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined
2021-05-01 25 techniques ๐Ÿ‡ฎ๐Ÿ‡ท VOID MANTICORE
C0043
Indian Critical Infrastructure Intrusions
Indian Critical Infrastructure Intrusions is a sequence of intrusions from 2021 through early 2022 linked to Peopleโ€™s Republic of China (PRC) threat actors, particularly RedEcho an
2021-01-01 8 techniques
C0050
J-magic Campaign
The J-magic Campaign was active from mid-2023 to at least mid-2024 and featured the use of the J-magic backdoor, a custom cd00r variant tailored for use against Juniper routers. Th
2023-06-01 4 techniques
C0044
Juicy Mix
Juicy Mix was a campaign conducted by OilRig throughout 2022 that targeted Israeli organizations with the Mango backdoor.
2022-01-01 14 techniques ๐Ÿ‡ฎ๐Ÿ‡ท OilRig
C0035
KV Botnet Activity
KV Botnet Activity consisted of exploitation of primarily โ€œend-of-lifeโ€ small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet
2022-10-01 20 techniques ๐Ÿ‡จ๐Ÿ‡ณ Volt Typhoon
C0049
Leviathan Australian Intrusions
Leviathan Australian Intrusions consisted of at least two long-term intrusions against victims in Australia by Leviathan, relying on similar tradecraft such as external service exp
2022-04-01 26 techniques ๐Ÿ‡จ๐Ÿ‡ณ Leviathan
C0002
Night Dragon
Night Dragon was a cyber espionage campaign that targeted oil, energy, and petrochemical companies, along with individuals and executives in Kazakhstan, Taiwan, Greece, and the Uni
2009-11-01 29 techniques
C0060
Operation AkaiRyลซ
Operation AkaiRyลซ (Japanese for RedDragon) was a cyberespionage spearphishing campaign conducted by MirrorFace between June and September 2024 against entities in Japan and Central
2004-06-01 26 techniques ๐Ÿ‡จ๐Ÿ‡ณ MirrorFace
C0012
Operation CuckooBees
Operation CuckooBees was a cyber espionage campaign targeting technology and manufacturing companies in East Asia, Western Europe, and North America since at least 2019. Security r
2019-12-01 33 techniques
C0061
Operation Digital Eye
Operation Digital Eye was conducted in June and July of 2024 by suspected People's Republic of China (PRC)-nexus threat actors targeting business-to-business IT service providers i
2024-06-01 22 techniques
C0022
Operation Dream Job
Operation Dream Job was a cyber espionage operation likely conducted by Lazarus Group that targeted the defense, aerospace, government, and other sectors in the United States, Isra
2019-09-01 55 techniques ๐Ÿ‡ฐ๐Ÿ‡ต Lazarus Group
C0016
Operation Dust Storm
Operation Dust Storm was a long-standing persistent cyber espionage campaign that targeted multiple industries in Japan, South Korea, the United States, Europe, and several Southea
2010-01-01 17 techniques
C0023
Operation Ghost
Operation Ghost was an APT29 campaign starting in 2013 that included operations against ministries of foreign affairs in Europe and the Washington, D.C. embassy of a European Union
2013-09-01 8 techniques ๐Ÿ‡ท๐Ÿ‡บ APT29
C0006
Operation Honeybee
Operation Honeybee was a campaign that targeted humanitarian aid and inter-Korean affairs organizations from at least late 2017 through early 2018. Operation Honeybee initially tar
2017-08-01 28 techniques
C0048
Operation MidnightEclipse
Operation MidnightEclipse was a campaign conducted in March and April 2024 that involved initial exploit of zero-day vulnerability CVE-2024-3400, a critical command injection vulne
2024-03-01 17 techniques
C0013
Operation Sharpshooter
Operation Sharpshooter was a global cyber espionage campaign that targeted nuclear, defense, government, energy, and financial companies, with many located in Germany, Turkey, the
2017-09-01 13 techniques
C0005
Operation Spalax
Operation Spalax was a campaign that primarily targeted Colombian government organizations and private companies, particularly those associated with the energy and metallurgical in
2019-11-01 17 techniques
C0014
Operation Wocao
Operation Wocao was a cyber espionage campaign that targeted organizations around the world, including in Brazil, China, France, Germany, Italy, Mexico, Portugal, Spain, the United
2017-12-01 70 techniques
C0042
Outer Space
Outer Space was a campaign conducted by OilRig throughout 2021 that used the SampleCheck5000 downloader and Solar backdoor to target Israeli organizations.
2021-01-01 8 techniques ๐Ÿ‡ฎ๐Ÿ‡ท OilRig
C0036
Pikabot Distribution February 2024
Pikabot was distributed in Pikabot Distribution February 2024 using malicious emails with embedded links leading to malicious ZIP archives requiring user interaction for follow-on
2024-02-01 4 techniques
C0055
Quad7 Activity
Quad7 Activity, also known as CovertNetwork-1658 or the 7777 Botnet, is a network of compromised small office/home office (SOHO) routers. The botnet was initially composed primaril
2023-08-01 15 techniques
C0047
RedDelta Modified PlugX Infection Chain Operations
RedDelta Modified PlugX Infection Chain Operations was executed by Mustang Panda from mid-2023 through the end of 2024 against multiple entities in East and Southeast Asia. RedDelt
2023-07-01 22 techniques ๐Ÿ‡ท๐Ÿ‡บ Mustang Panda
C0056
RedPenguin
The RedPenguin project was launched by Juniper in July 2024 to investigate reported malware infections of Juniper MX Series routers. RedPenguin activity was separately attributed t
2024-07-01 26 techniques ๐Ÿ‡จ๐Ÿ‡ณ UNC3886
C0052
SPACEHOP Activity
SPACEHOP Activity is conducted through commercially leased Virtual Private Servers (VPS), otherwise known as provisioned Operational Relay Box (ORB) networks. The network leveraged
2019-01-01 4 techniques ๐Ÿ‡จ๐Ÿ‡ณ Ke3chang๐Ÿ‡จ๐Ÿ‡ณ APT5
C0059
Salesforce Data Exfiltration
The Salesforce Data Exfiltration campaign began in October 2024 with financially-motivated threat actor UNC6040 using Spearphishing Voice (vishing) to compromise corporate Salesfor
2004-10-01 18 techniques
C0045
ShadowRay
ShadowRay was a campaign that began in late 2023 targeting the education, cryptocurrency, biopharma, and other sectors through a vulnerability (CVE-2023-48022) in the Ray AI framew
2023-09-01 10 techniques
C0058
SharePoint ToolShell Exploitation
The SharePoint ToolShell Exploitation campaign was conducted in July 2025 and encompassed the first waves of exploitation against incompletely patched spoofing (CVE-2025-49706) and
2025-07-01 35 techniques
C0024
SolarWinds Compromise
The SolarWinds Compromise was a sophisticated supply chain cyber operation conducted by APT29 that was discovered in mid-December 2020. APT29 used customized malware to inject mali
2019-08-01 71 techniques ๐Ÿ‡ท๐Ÿ‡บ APT29
C0030
Triton Safety Instrumented System Attack
Triton Safety Instrumented System Attack was a campaign employed by TEMP.Veles which leveraged the Triton malware framework against a petrochemical organization. The malware and te
2017-06-01 10 techniques ๐Ÿ‡ท๐Ÿ‡บ TEMP.Veles
C0039
Versa Director Zero Day Exploitation
Versa Director Zero Day Exploitation was conducted by Volt Typhoon from early June through August 2024 as zero-day exploitation of Versa Director servers controlling software-defin
2024-06-01 8 techniques ๐Ÿ‡จ๐Ÿ‡ณ Volt Typhoon
C0037
Water Curupira Pikabot Distribution
Pikabot was distributed in Water Curupira Pikabot Distribution throughout 2023 by an entity linked to BlackBasta ransomware deployment via email attachments. This activity followed
2023-01-01 10 techniques
โ†‘