G1030
Agrius
Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius
๐ฎ๐ท Iran
22 techniques
9 software
G0130
Ajax Security Team
Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten
Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-b
๐ฎ๐ท Iran
6 techniques
2 software
G0138
Andariel
Silent Chollima, PLUTONIUM, Onyx Sleet
Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South
๐ฐ๐ต North Korea
12 techniques
2 software
G1049
AppleJeus
Gleaming Pisces, Citrine Sleet, UNC1720, UNC4736
AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader Lazarus Group umbrella of actors, AppleJeus has been active since
๐ฐ๐ต North Korea
2 techniques
0 software
G1028
APT-C-23
Mantis, Arid Viper, Desert Falcon, TAG-63
APT-C-23 is a threat group that has been active since at least 2014. APT-C-23 has primarily focused its operations on the Middle East, including Israeli military assets. APT-C-23 has developed mobile
0 techniques
1 software
G0006
APT1
Comment Crew, Comment Group, Comment Panda
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the Peopleโs Liberation Army (PLA) General Staff Departmentโs (GSD) 3rd Department, commonly known by its Military Unit Cov
๐จ๐ณ China
23 techniques
17 software
G0005
APT12
IXESHE, DynCalc, Numbered Panda, DNSCALC
APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.
๐จ๐ณ China
5 techniques
3 software
G0025
APT17
Deputy Dog
APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non
๐จ๐ณ China
2 techniques
1 software
G0026
APT18
TG-0416, Dynamite Panda, Threat Group-0416
APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.
12 techniques
5 software
G0073
APT19
Codoso, C0d0so0, Codoso Team, Sunshop Group
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal
๐จ๐ณ China
21 techniques
2 software
G0007
APT28
IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active
๐ท๐บ Russia
93 techniques
29 software
G0016
APT29
IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo
APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member cou
๐ท๐บ Russia
66 techniques
49 software
G0022
APT3
Gothic Panda, Pirpi, UPS Team, Buckeye
APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Cla
๐จ๐ณ China
44 techniques
6 software
G0050
APT32
SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and jour
๐ป๐ณ Vietnam
78 techniques
15 software
G0064
APT33
HOLMIUM, Elfin, Peach Sandstorm
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and S
๐ฎ๐ท Iran
31 techniques
16 software
G0067
APT37
InkySquid, ScarCruft, Reaper, Group123
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nep
๐ท๐บ Russia
29 techniques
13 software
G0082
APT38
NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has
๐ฐ๐ต North Korea
56 techniques
6 software
G0087
APT39
ITG07, Chafer, Remix Kitten
APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 20
๐ฎ๐ท Iran
53 techniques
11 software
G0096
APT41
Wicked Panda, Brass Typhoon, BARIUM
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observ
๐จ๐ณ China
82 techniques
32 software
G1023
APT5
Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5
๐จ๐ณ China
29 techniques
13 software
G0001
Axiom
Group 72
Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overl
๐จ๐ณ China
16 techniques
8 software
G1002
BITTER
T-APT-17
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangl
๐จ๐ณ China
16 techniques
1 software
G1021
Cinnamon Tempest
DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operat
๐จ๐ณ China
19 techniques
8 software
G1052
Contagious Interview
DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER
Contagious Interview is a North Koreaโaligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and use
๐ฐ๐ต North Korea
54 techniques
4 software
G0052
CopyKittens
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group
๐ฎ๐ท Iran
8 techniques
4 software
G1012
CURIUM
Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc
CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East. CURIUM has since invested in building relati
๐ฎ๐ท Iran
19 techniques
1 software
G1034
Daggerfly
Evasive Panda, BRONZE HIGHLAND
Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Afr
๐จ๐ณ China
17 techniques
6 software
G0009
Deep Panda
Shell Crew, WebMasters, KungFu Kittens, PinkPanther
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been
๐จ๐ณ China
10 techniques
7 software
G0035
Dragonfly
TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192
Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, g
๐ท๐บ Russia
56 techniques
10 software
G1006
Earth Lusca
TAG-22, Charcoal Typhoon, CHROMIUM, ControlX
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the
๐จ๐ณ China
44 techniques
9 software
G0066
Elderwood
Elderwood Gang, Beijing Group, Sneaky Panda
Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. The group has targeted defense organizations, supply cha
๐จ๐ณ China
9 techniques
9 software
G1003
Ember Bear
UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard
Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training C
๐ท๐บ Russia
47 techniques
11 software
G0037
FIN6
Magecart Group 6, ITG08, Skeleton Spider, TAAL
FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in th
40 techniques
12 software
G0046
FIN7
GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud
67 techniques
19 software
G0061
FIN8
Syssphinx
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, c
36 techniques
11 software
G0117
Fox Kitten
UNC757, Parisite, Pioneer Kitten, RUBIDIUM
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North Ame
๐ฎ๐ท Iran
41 techniques
5 software
G0093
GALLIUM
Granite Typhoon
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia,
๐ท๐บ Russia
31 techniques
16 software
G0047
Gamaredon Group
IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The
๐ท๐บ Russia
70 techniques
6 software
G1001
HEXANE
Lyceum, Siamesekitten, Spirlin
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been locate
36 techniques
12 software
G0126
Higaisa
Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China,
๐ท๐บ Russia
28 techniques
3 software
G0100
Inception
Inception Framework, Cloud Atlas
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States
๐ท๐บ Russia
22 techniques
3 software
G0119
Indrik Spider
Evil Corp, Manatee Tempest, DEV-0243, UNC2165
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransom
๐ท๐บ Russia
33 techniques
8 software
G0004
Ke3chang
APT15, Mirage, Vixen Panda, GREF
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and N
๐จ๐ณ China
46 techniques
11 software
G0094
Kimsuky
Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tan
๐ท๐บ Russia
130 techniques
19 software
G0032
Lazarus Group
Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsibl
๐ฐ๐ต North Korea
93 techniques
26 software
G0065
Leviathan
MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active
๐จ๐ณ China
50 techniques
17 software
G0030
Lotus Blossom
DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities su
21 techniques
9 software
G0059
Magic Hound
TA453, COBALT ILLUSION, Charming Kitten, ITG18
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted E
๐ฎ๐ท Iran
78 techniques
13 software
G0045
menuPass
Cicada, POTASSIUM, Stone Panda, APT10
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin S
๐จ๐ณ China
46 techniques
25 software
G0021
Molerats
Operation Molerats, Gaza Cybergang
Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.
16 techniques
6 software
G0069
MuddyWater
Earth Vetala, MERCURY, Static Kitten, Seedworm
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of governmen
๐ฎ๐ท Iran
68 techniques
21 software
G0129
Mustang Panda
TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to
๐ท๐บ Russia
85 techniques
23 software
G0133
Nomadic Octopus
DustSquad
Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nom
๐ท๐บ Russia
7 techniques
1 software
G0049
OilRig
COBALT GYPSY, IRN2, APT34, Helix Kitten
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government,
๐ฎ๐ท Iran
76 techniques
30 software
G0040
Patchwork
Hangover Group, Dropping Elephant, Chinastrats, MONSOON
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or I
๐จ๐ณ China
41 techniques
8 software
G1005
POLONIUM
Plaid Rain
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2
๐ฎ๐ท Iran
7 techniques
2 software
G1039
RedCurl
RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including b
๐ท๐บ Russia
41 techniques
0 software
G1031
Saint Bear
Storm-0587, TA471, UAC-0056, Lorec53
Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and informat
๐ท๐บ Russia
18 techniques
2 software
G0034
Sandworm Team
ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group)
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. Thi
๐ท๐บ Russia
79 techniques
27 software
G1015
Scattered Spider
Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcin
64 techniques
9 software
G1041
Sea Turtle
Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON
Sea Turtle is a Tรผrkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is
27 techniques
1 software
G1033
Star Blizzard
SEABORGIUM, Callisto Group, TA446, COLDRIVER
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have inclu
๐ท๐บ Russia
20 techniques
1 software
G0041
Strider
ProjectSauron
Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.
๐ท๐บ Russia
3 techniques
1 software
G0092
TA505
Hive0065, Spandex Tempest, CHIMBORAZO
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaig
34 techniques
16 software
G1056
TeamPCP
PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058
TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 202
36 techniques
3 software
G0027
Threat Group-3390
Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the a
๐จ๐ณ China
57 techniques
24 software
G0131
Tonto Team
Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded
๐จ๐ณ China
15 techniques
6 software
G0134
Transparent Tribe
COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM
Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.
๐ต๐ฐ Pakistan
14 techniques
5 software
G0010
Turla
IRON HUNTER, Group 88, Waterbug, WhiteBear
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of
๐ท๐บ Russia
68 techniques
30 software
G1055
VOID MANTICORE
COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma
VOID MANTICORE is a threat group assessed to operate on behalf of Iranโs Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities,
๐ฎ๐ท Iran
63 techniques
0 software
G1017
Volt Typhoon
BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territori
๐จ๐ณ China
81 techniques
17 software
G0102
Wizard Spider
UNC1878, TEMP.MixMaster, Grim Spider, FIN12
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools
๐ท๐บ Russia
64 techniques
22 software