176 of 176 shown
G0018
admin@338
admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade
๐Ÿ‡จ๐Ÿ‡ณ China 12 techniques 7 software
G1030
Agrius
Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow
Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets. Public reporting has linked Agrius
๐Ÿ‡ฎ๐Ÿ‡ท Iran 22 techniques 9 software
G0130
Ajax Security Team
Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten
Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-b
๐Ÿ‡ฎ๐Ÿ‡ท Iran 6 techniques 2 software
G1024
Akira
GOLD SAHARA, PUNK SPIDER, Howling Scorpius
Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access single-factor external access mechanisms such as VPNs for
17 techniques 8 software
G0138
Andariel
Silent Chollima, PLUTONIUM, Onyx Sleet
Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its operations--which have included destructive attacks--against South
๐Ÿ‡ฐ๐Ÿ‡ต North Korea 12 techniques 2 software
G1007
Aoqin Dragon
Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organization
๐Ÿ‡จ๐Ÿ‡ณ China 9 techniques 2 software
G1049
AppleJeus
Gleaming Pisces, Citrine Sleet, UNC1720, UNC4736
AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader Lazarus Group umbrella of actors, AppleJeus has been active since
๐Ÿ‡ฐ๐Ÿ‡ต North Korea 2 techniques 0 software
G1028
APT-C-23
Mantis, Arid Viper, Desert Falcon, TAG-63
APT-C-23 is a threat group that has been active since at least 2014. APT-C-23 has primarily focused its operations on the Middle East, including Israeli military assets. APT-C-23 has developed mobile
0 techniques 1 software
G0099
APT-C-36
Blind Eagle, TAG-144, AguilaCiega, APT-Q-98
APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36 has targeted government institutions and entities i
38 techniques 9 software
G0006
APT1
Comment Crew, Comment Group, Comment Panda
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the Peopleโ€™s Liberation Army (PLA) General Staff Departmentโ€™s (GSD) 3rd Department, commonly known by its Military Unit Cov
๐Ÿ‡จ๐Ÿ‡ณ China 23 techniques 17 software
G0005
APT12
IXESHE, DynCalc, Numbered Panda, DNSCALC
APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets, high-tech companies, and multiple governments.
๐Ÿ‡จ๐Ÿ‡ณ China 5 techniques 3 software
G0023
APT16
APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations.
๐Ÿ‡จ๐Ÿ‡ณ China 1 techniques 1 software
G0025
APT17
Deputy Dog
APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non
๐Ÿ‡จ๐Ÿ‡ณ China 2 techniques 1 software
G0026
APT18
TG-0416, Dynamite Panda, Threat Group-0416
APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.
12 techniques 5 software
G0073
APT19
Codoso, C0d0so0, Codoso Team, Sunshop Group
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal
๐Ÿ‡จ๐Ÿ‡ณ China 21 techniques 2 software
G0007
APT28
IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74
APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active
๐Ÿ‡ท๐Ÿ‡บ Russia 93 techniques 29 software
G0016
APT29
IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo
APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member cou
๐Ÿ‡ท๐Ÿ‡บ Russia 66 techniques 49 software
G0022
APT3
Gothic Panda, Pirpi, UPS Team, Buckeye
APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the campaigns known as Operation Clandestine Fox, Operation Cla
๐Ÿ‡จ๐Ÿ‡ณ China 44 techniques 6 software
G0013
APT30
APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches.
๐Ÿ‡จ๐Ÿ‡ณ China 2 techniques 5 software
G0050
APT32
SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and jour
๐Ÿ‡ป๐Ÿ‡ณ Vietnam 78 techniques 15 software
G0064
APT33
HOLMIUM, Elfin, Peach Sandstorm
APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple industries in the United States, Saudi Arabia, and S
๐Ÿ‡ฎ๐Ÿ‡ท Iran 31 techniques 16 software
G0067
APT37
InkySquid, ScarCruft, Reaper, Group123
APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nep
๐Ÿ‡ท๐Ÿ‡บ Russia 29 techniques 13 software
G0082
APT38
NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima
APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau. Active since at least 2014, APT38 has
๐Ÿ‡ฐ๐Ÿ‡ต North Korea 56 techniques 6 software
G0087
APT39
ITG07, Chafer, Remix Kitten
APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front company Rana Intelligence Computing since at least 20
๐Ÿ‡ฎ๐Ÿ‡ท Iran 53 techniques 11 software
G0096
APT41
Wicked Panda, Brass Typhoon, BARIUM
APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated operations. Active since at least 2012, APT41 has been observ
๐Ÿ‡จ๐Ÿ‡ณ China 82 techniques 32 software
G1044
APT42
APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East region, but has targeted a variety of industries an
๐Ÿ‡ฎ๐Ÿ‡ท Iran 32 techniques 2 software
G1023
APT5
Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda
APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5
๐Ÿ‡จ๐Ÿ‡ณ China 29 techniques 13 software
G0143
Aquatic Panda
Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least May 2020, Aquatic Panda has primarily targeted enti
๐Ÿ‡จ๐Ÿ‡ณ China 35 techniques 6 software
G0001
Axiom
Group 72
Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at least 2008. Some reporting suggests a degree of overl
๐Ÿ‡จ๐Ÿ‡ณ China 16 techniques 8 software
G0135
BackdoorDiplomacy
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Eu
15 techniques 5 software
G1002
BITTER
T-APT-17
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangl
๐Ÿ‡จ๐Ÿ‡ณ China 16 techniques 1 software
G1043
BlackByte
Hecamede
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled BlackByte Ransomware. BlackByte ransomware operations ini
48 techniques 8 software
G0063
BlackOasis
BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in the United Nations, as well as opposition bloggers, a
1 techniques 0 software
G0098
BlackTech
Palmerworm
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong Kong--and the US since at least 2013. BlackTech has
๐Ÿ‡จ๐Ÿ‡ณ China 14 techniques 6 software
G0108
Blue Mockingbird
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows systems. The earliest observed Blue Mockingbird tools w
22 techniques 2 software
G0060
BRONZE BUTLER
REDBALDKNIGHT, Tick
BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese organizations, particularly those in government, bio
๐Ÿ‡จ๐Ÿ‡ณ China 40 techniques 14 software
G0008
Carbanak
Anunak
Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7 that
9 techniques 4 software
G0114
Chimera
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as data from the airline industry.
๐Ÿ‡จ๐Ÿ‡ณ China 59 techniques 6 software
G1021
Cinnamon Tempest
DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked Babuk source code. Cinnamon Tempest does not operat
๐Ÿ‡จ๐Ÿ‡ณ China 19 techniques 8 software
G0003
Cleaver
Threat Group 2889, TG-2889
Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong circumstantial evidence suggests Cleaver is linked to Threat G
๐Ÿ‡ฎ๐Ÿ‡ท Iran 5 techniques 4 software
G0080
Cobalt Group
GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted intrusions to steal money via targeting ATM systems
34 techniques 6 software
G0142
Confucius
Confucius APT
Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Secur
19 techniques 1 software
G1052
Contagious Interview
DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER
Contagious Interview is a North Koreaโ€“aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the theft of cryptocurrency and use
๐Ÿ‡ฐ๐Ÿ‡ต North Korea 54 techniques 4 software
G0052
CopyKittens
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi Arabia, Turkey, the U.S., Jordan, and Germany. The group
๐Ÿ‡ฎ๐Ÿ‡ท Iran 8 techniques 4 software
G1012
CURIUM
Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc
CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle East. CURIUM has since invested in building relati
๐Ÿ‡ฎ๐Ÿ‡ท Iran 19 techniques 1 software
G1034
Daggerfly
Evasive Panda, BRONZE HIGHLAND
Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO entities, and telecommunication companies in Asia and Afr
๐Ÿ‡จ๐Ÿ‡ณ China 17 techniques 6 software
G0070
Dark Caracal
Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least 2012.
๐Ÿ‡ฑ๐Ÿ‡ง Lebanon 12 techniques 3 software
G0012
Darkhotel
DUBNIUM, Zigzag Hail
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on cyber espionage operations conducted via hotel Int
๐Ÿ‡ฐ๐Ÿ‡ท South Korea 24 techniques 0 software
G0079
DarkHydrus
DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group heavily leverages open-source tools and custom payload
7 techniques 3 software
G0105
DarkVishnya
DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8 banks in this region.
10 techniques 2 software
G0009
Deep Panda
Shell Crew, WebMasters, KungFu Kittens, PinkPanther
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The intrusion into healthcare company Anthem has been
๐Ÿ‡จ๐Ÿ‡ณ China 10 techniques 7 software
G0035
Dragonfly
TEMP.Isotope, DYMALLOY, Berserk Bear, TG-4192
Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010, Dragonfly has targeted defense and aviation companies, g
๐Ÿ‡ท๐Ÿ‡บ Russia 56 techniques 10 software
G0017
DragonOK
DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools, DragonOK is thought to have a direct or indirect rela
0 techniques 2 software
G1006
Earth Lusca
TAG-22, Charcoal Typhoon, CHROMIUM, ControlX
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the
๐Ÿ‡จ๐Ÿ‡ณ China 44 techniques 9 software
G0066
Elderwood
Elderwood Gang, Beijing Group, Sneaky Panda
Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. The group has targeted defense organizations, supply cha
๐Ÿ‡จ๐Ÿ‡ณ China 9 techniques 9 software
G1003
Ember Bear
UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard
Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training C
๐Ÿ‡ท๐Ÿ‡บ Russia 47 techniques 11 software
G0020
Equation
Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the capability to overwrite the firmware of hard disk
4 techniques 0 software
G0120
Evilnum
Evilnum is a financially motivated threat group that has been active since at least 2018.
11 techniques 3 software
G1011
EXOTIC LILY
EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and Diavol. EXOTIC LILY may be acting as an initial access
15 techniques 2 software
G0137
Ferocious Kitten
Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.
๐Ÿ‡ฎ๐Ÿ‡ท Iran 6 techniques 2 software
G0051
FIN10
FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses stolen data exfiltrated from victims to extort organizat
11 techniques 1 software
G1016
FIN13
Elephant Beetle
FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America, as early as 2016. FIN13 achieves its objectives by
53 techniques 4 software
G0085
FIN4
FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly regarding healthcare and pharmaceutical companies, since at
12 techniques 0 software
G0053
FIN5
FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been active since at least 2008 and has targeted the rest
๐Ÿ‡ท๐Ÿ‡บ Russia 11 techniques 6 software
G0037
FIN6
Magecart Group 6, ITG08, Skeleton Spider, TAAL
FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively targeted and compromised point of sale (PoS) systems in th
40 techniques 12 software
G0046
FIN7
GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud
67 techniques 19 software
G0061
FIN8
Syssphinx
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the hospitality, retail, entertainment, insurance, technology, c
36 techniques 11 software
G0117
Fox Kitten
UNC757, Parisite, Pioneer Kitten, RUBIDIUM
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle East, North Africa, Europe, Australia, and North Ame
๐Ÿ‡ฎ๐Ÿ‡ท Iran 41 techniques 5 software
G0093
GALLIUM
Granite Typhoon
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia,
๐Ÿ‡ท๐Ÿ‡บ Russia 31 techniques 16 software
G0084
Gallmaker
Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and g
6 techniques 0 software
G0047
Gamaredon Group
IRON TILDEN, Primitive Bear, ACTINIUM, Armageddon
Gamaredon Group is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The
๐Ÿ‡ท๐Ÿ‡บ Russia 70 techniques 6 software
G0036
GCMAN
GCMAN is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services.
2 techniques 0 software
G0115
GOLD SOUTHFIELD
Pinchy Spider
GOLD SOUTHFIELD is a financially motivated threat group active since at least 2018 that operates the REvil Ransomware-as-a Service (RaaS). GOLD SOUTHFIELD provides backend infrastructure for affiliate
9 techniques 2 software
G0078
Gorgon Group
Gorgon Group is a threat group consisting of members who are suspected to be Pakistan-based or have other connections to Pakistan. The group has performed a mix of criminal and targeted attacks, inclu
๐Ÿ‡ท๐Ÿ‡บ Russia 16 techniques 4 software
G0043
Group5
Group5 is a threat group with a suspected Iranian nexus, though this attribution is not definite. The group has targeted individuals connected to the Syrian opposition via spearphishing and watering h
๐Ÿ‡ฎ๐Ÿ‡ท Iran 4 techniques 2 software
G0125
HAFNIUM
Operation Exchange Marauder, Silk Typhoon
HAFNIUM is a likely state-sponsored cyber espionage group operating out of China that has been active since at least January 2021. HAFNIUM primarily targets entities in the US across a number of indus
๐Ÿ‡จ๐Ÿ‡ณ China 44 techniques 6 software
G1001
HEXANE
Lyceum, Siamesekitten, Spirlin
HEXANE is a cyber espionage threat group that has targeted oil & gas, telecommunications, aviation, and internet service provider organizations since at least 2017. Targeted companies have been locate
36 techniques 12 software
G0126
Higaisa
Higaisa is a threat group suspected to have South Korean origins. Higaisa has targeted government, public, and trade organizations in North Korea; however, they have also carried out attacks in China,
๐Ÿ‡ท๐Ÿ‡บ Russia 28 techniques 3 software
G1032
INC Ransom
GOLD IONIC
INC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwi
25 techniques 8 software
G0100
Inception
Inception Framework, Cloud Atlas
Inception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States
๐Ÿ‡ท๐Ÿ‡บ Russia 22 techniques 3 software
G0136
IndigoZebra
IndigoZebra is a suspected Chinese cyber espionage group that has been targeting Central Asian governments since at least 2014.
๐Ÿ‡จ๐Ÿ‡ณ China 7 techniques 3 software
G0119
Indrik Spider
Evil Corp, Manatee Tempest, DEV-0243, UNC2165
Indrik Spider is a Russia-based cybercriminal group that has been active since at least 2014. Indrik Spider initially started with the Dridex banking Trojan, and then by 2017 they began running ransom
๐Ÿ‡ท๐Ÿ‡บ Russia 33 techniques 8 software
G0004
Ke3chang
APT15, Mirage, Vixen Panda, GREF
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and N
๐Ÿ‡จ๐Ÿ‡ณ China 46 techniques 11 software
G0094
Kimsuky
Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tan
๐Ÿ‡ท๐Ÿ‡บ Russia 130 techniques 19 software
G1004
LAPSUS$
DEV-0537, Strawberry Tempest
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks witho
43 techniques 1 software
G0032
Lazarus Group
Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsibl
๐Ÿ‡ฐ๐Ÿ‡ต North Korea 93 techniques 26 software
G0140
LazyScripter
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.
20 techniques 7 software
G0077
Leafminer
Raspite
Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.
๐Ÿ‡ฎ๐Ÿ‡ท Iran 17 techniques 4 software
G0065
Leviathan
MUDCARP, Kryptonite Panda, Gadolinium, BRONZE MOHAWK
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security Department and an affiliated front company. Active
๐Ÿ‡จ๐Ÿ‡ณ China 50 techniques 17 software
G0030
Lotus Blossom
DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities su
21 techniques 9 software
G1014
LuminousMoth
LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile organizations, including government entities, in Myanm
๐Ÿ‡จ๐Ÿ‡ณ China 28 techniques 2 software
G0095
Machete
APT-C-43, El Machete
Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations within Latin America, with a particular emphasis on Vene
๐Ÿ‡ท๐Ÿ‡บ Russia 11 techniques 1 software
G0059
Magic Hound
TA453, COBALT ILLUSION, Charming Kitten, ITG18
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted E
๐Ÿ‡ฎ๐Ÿ‡ท Iran 78 techniques 13 software
G1026
Malteiro
Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group operates and distributes the Mispadu banking trojan via a
12 techniques 1 software
G1051
Medusa Group
Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a Ransomware-as-a-Service (RaaS) operation. Some reporting indicates that
57 techniques 5 software
G0045
menuPass
Cicada, POTASSIUM, Stone Panda, APT10
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin S
๐Ÿ‡จ๐Ÿ‡ณ China 46 techniques 25 software
G1013
Metador
Metador is a suspected cyber espionage group that was first reported in September 2022. Metador has targeted a limited number of telecommunication companies, internet service providers, and universiti
9 techniques 2 software
G1054
MirrorFace
Earth Kasha
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on targeting, tools, and infrastructure overlaps. MirrorFace h
๐Ÿ‡จ๐Ÿ‡ณ China 43 techniques 16 software
G0002
Moafee
Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationsh
๐Ÿ‡จ๐Ÿ‡ณ China 1 techniques 1 software
G0103
Mofang
Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focuse
๐Ÿ‡จ๐Ÿ‡ณ China 6 techniques 2 software
G0021
Molerats
Operation Molerats, Gaza Cybergang
Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the Middle East, Europe, and the United States.
16 techniques 6 software
G1036
Moonstone Sleet
Storm-1789
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously overlapped significantly with another North Korean-lin
๐Ÿ‡ฐ๐Ÿ‡ต North Korea 30 techniques 1 software
G1009
Moses Staff
DEV-0500, Marigold Sandstorm
Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. Moses Staff openly stated their motivation in attacking Israeli companies i
๐Ÿ‡ฎ๐Ÿ‡ท Iran 12 techniques 4 software
G1019
MoustachedBouncer
MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.
๐Ÿ‡ง๐Ÿ‡พ Belarus 8 techniques 3 software
G0069
MuddyWater
Earth Vetala, MERCURY, Static Kitten, Seedworm
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of governmen
๐Ÿ‡ฎ๐Ÿ‡ท Iran 68 techniques 21 software
G0129
Mustang Panda
TA416, RedDelta, BRONZE PRESIDENT, STATELY TAURUS
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to use tailored phishing lures and decoy documents to
๐Ÿ‡ท๐Ÿ‡บ Russia 85 techniques 23 software
G1020
Mustard Tempest
DEV-0206, TA569, GOLD PRELUDE, UNC1543
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered with Indrik Spider to provide access for the downlo
12 techniques 2 software
G0019
Naikon
Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese Peopleโ€™s Liberation Armyโ€™s (PLA) Chengdu Military Region Second Technical Reconnaissance Bureau (Military Uni
๐Ÿ‡จ๐Ÿ‡ณ China 14 techniques 15 software
G0055
NEODYMIUM
NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity to another activity group called PROMETHIUM due to
๐Ÿ‡น๐Ÿ‡ท Turkey 0 techniques 1 software
G0133
Nomadic Octopus
DustSquad
Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic missions, and individuals, since at least 2014. Nom
๐Ÿ‡ท๐Ÿ‡บ Russia 7 techniques 1 software
G0049
OilRig
COBALT GYPSY, IRN2, APT34, Helix Kitten
OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including financial, government,
๐Ÿ‡ฎ๐Ÿ‡ท Iran 76 techniques 30 software
G0071
Orangeworm
Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for the purpose of corporate espionage. Reverse engine
2 techniques 8 software
G0040
Patchwork
Hangover Group, Dropping Elephant, Chinastrats, MONSOON
Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial evidence suggests the group may be a pro-Indian or I
๐Ÿ‡จ๐Ÿ‡ณ China 41 techniques 8 software
G0011
PittyTiger
PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.
๐Ÿ‡จ๐Ÿ‡ณ China 2 techniques 5 software
G0068
PLATINUM
PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related organizations in South and Southeast Asia.
11 techniques 3 software
G1040
Play
Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North Ame
26 techniques 9 software
G1005
POLONIUM
Plaid Rain
POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and defense industry companies, since at least February 2
๐Ÿ‡ฎ๐Ÿ‡ท Iran 7 techniques 2 software
G0033
Poseidon Group
Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information exfiltrated from victims to blackmail victim companies into
8 techniques 0 software
G0056
PROMETHIUM
StrongPity
PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a heavy emphasis on Turkish targets. PROMETHIUM has demo
๐Ÿ‡น๐Ÿ‡ท Turkey 11 techniques 2 software
G0024
Putter Panda
APT2, MSUpdater
Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLAโ€™s 3rd General Staff Department (GSD).
๐Ÿ‡จ๐Ÿ‡ณ China 4 techniques 4 software
G0075
Rancor
Rancor is a threat group that has led targeted campaigns against the South East Asia region. Rancor uses politically-motivated lures to entice victims to open malicious documents.
9 techniques 4 software
G1039
RedCurl
RedCurl is a threat actor active since 2018 notable for corporate espionage targeting a variety of locations, including Ukraine, Canada and the United Kingdom, and a variety of industries, including b
๐Ÿ‡ท๐Ÿ‡บ Russia 41 techniques 0 software
G1042
RedEcho
RedEcho is a Peopleโ€™s Republic of China-related threat actor associated with long-running intrusions in Indian critical infrastructure entities. RedEcho overlaps with various other PRC-linked threat g
๐Ÿ‡จ๐Ÿ‡ณ China 5 techniques 1 software
G0106
Rocke
Rocke is an alleged Chinese-speaking adversary whose primary objective appeared to be cryptojacking, or stealing victim system resources for the purposes of mining cryptocurrency. The name Rocke comes
๐Ÿ‡จ๐Ÿ‡ณ China 36 techniques 0 software
G0048
RTM
RTM is a cybercriminal group that has been active since at least 2015 and is primarily interested in users of remote banking systems in Russia and neighboring countries. The group uses a Trojan by the
๐Ÿ‡ท๐Ÿ‡บ Russia 7 techniques 1 software
G1031
Saint Bear
Storm-0587, TA471, UAC-0056, Lorec53
Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and informat
๐Ÿ‡ท๐Ÿ‡บ Russia 18 techniques 2 software
G1045
Salt Typhoon
Salt Typhoon is a People's Republic of China (PRC) state-backed actor that has been active since at least 2019 and responsible for numerous compromises of network infrastructure at major U.S. telecomm
๐Ÿ‡จ๐Ÿ‡ณ China 14 techniques 1 software
G0034
Sandworm Team
ELECTRUM, Telebots, IRON VIKING, BlackEnergy (Group)
Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455. Thi
๐Ÿ‡ท๐Ÿ‡บ Russia 79 techniques 27 software
G0029
Scarlet Mimic
Scarlet Mimic is a threat group that has targeted minority rights activists. This group has not been directly linked to a government source, but the group's motivations appear to overlap with those of
๐Ÿ‡จ๐Ÿ‡ณ China 1 techniques 4 software
G1015
Scattered Spider
Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944
Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcin
64 techniques 9 software
G1041
Sea Turtle
Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON
Sea Turtle is a Tรผrkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is
27 techniques 1 software
G1057
ShinyHunters
UNC6240, Bling Libra
ShinyHunters is a cyber criminal collective that has been active since at least 2019 operating under the ShinyCorp persona. ShinyHunters has targeted multiple industries and geographic regions gatheri
46 techniques 1 software
G1008
SideCopy
SideCopy is a Pakistani threat group that has primarily targeted South Asian countries, including Indian and Afghani government personnel, since at least 2019. SideCopy's name comes from its infection
๐Ÿ‡ต๐Ÿ‡ฐ Pakistan 16 techniques 2 software
G0121
Sidewinder
T-APT-04, Rattlesnake
Sidewinder is a suspected Indian threat actor group that has been active since at least 2012. They have been observed targeting government, military, and business entities throughout Asia, primarily f
๐Ÿ‡จ๐Ÿ‡ณ China 30 techniques 1 software
G0091
Silence
Whisper Spider
Silence is a financially motivated threat actor targeting financial institutions in different countries. The group was first seen in June 2016. Their main targets reside in Russia, Ukraine, Belarus, A
๐Ÿ‡ท๐Ÿ‡บ Russia 28 techniques 3 software
G0122
Silent Librarian
TA407, COBALT DICKENS
Silent Librarian is a group that has targeted research and proprietary data at universities, government agencies, and private sector companies worldwide since at least 2013. Members of Silent Libraria
๐Ÿ‡ฎ๐Ÿ‡ท Iran 13 techniques 0 software
G0083
SilverTerrier
SilverTerrier is a Nigerian threat group that has been seen active since 2014. SilverTerrier mainly targets organizations in high technology, higher education, and manufacturing.
4 techniques 5 software
G0054
Sowbug
Sowbug is a threat group that has conducted targeted attacks against organizations in South America and Southeast Asia, particularly government entities, since at least 2015.
9 techniques 2 software
G1033
Star Blizzard
SEABORGIUM, Callisto Group, TA446, COLDRIVER
Star Blizzard is a cyber espionage and influence group originating in Russia that has been active since at least 2019. Star Blizzard campaigns align closely with Russian state interests and have inclu
๐Ÿ‡ท๐Ÿ‡บ Russia 20 techniques 1 software
G0038
Stealth Falcon
Stealth Falcon is a threat group that has conducted targeted spyware attacks against Emirati journalists, activists, and dissidents since at least 2012. Circumstantial evidence suggests there could be
16 techniques 0 software
G1053
Storm-0501
Storm-0501 is a financially motivated cyber criminal group that uses commodity and open-source tools to conduct ransomware operations. Storm-0501 has been active since 2021 and has previously been aff
42 techniques 8 software
G1046
Storm-1811
Storm-1811 is a financially-motivated entity linked to Black Basta ransomware deployment. Storm-1811 is notable for unique phishing and social engineering mechanisms for initial access, such as overlo
31 techniques 7 software
G0041
Strider
ProjectSauron
Strider is a threat group that has been active since at least 2011 and has targeted victims in Russia, China, Sweden, Belgium, Iran, and Rwanda.
๐Ÿ‡ท๐Ÿ‡บ Russia 3 techniques 1 software
G0039
Suckfly
Suckfly is a China-based threat group that has been active since at least 2014.
๐Ÿ‡จ๐Ÿ‡ณ China 5 techniques 1 software
G1018
TA2541
TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume a
28 techniques 9 software
G0062
TA459
TA459 is a threat group believed to operate out of China that has targeted countries including Russia, Belarus, Mongolia, and others.
๐Ÿ‡ท๐Ÿ‡บ Russia 5 techniques 4 software
G0092
TA505
Hive0065, Spandex Tempest, CHIMBORAZO
TA505 is a cyber criminal group that has been active since at least 2014. TA505 is known for frequently changing malware, driving global trends in criminal malware distribution, and ransomware campaig
34 techniques 16 software
G0127
TA551
GOLD CABIN, Shathak
TA551 is a financially-motivated threat group that has been active since at least 2018. The group has primarily targeted English, German, Italian, and Japanese speakers through email-based malware dis
14 techniques 5 software
G1037
TA577
TA577 is an initial access broker (IAB) that has distributed QakBot and Pikabot, and was among the first observed groups distributing Latrodectus in 2023.
6 techniques 3 software
G1038
TA578
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
4 techniques 3 software
G1056
TeamPCP
PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058
TeamPCP is a financially-motivated, cloud-native threat group that has been active since at least September 2025. Initially focused on ransomware and cryptocurrency theft, TeamPCP shifted in early 202
36 techniques 3 software
G0139
TeamTNT
TeamTNT is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its efforts on leveraging cloud
56 techniques 4 software
G0088
TEMP.Veles
XENOTIME
TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.
๐Ÿ‡ท๐Ÿ‡บ Russia 0 techniques 2 software
G0089
The White Company
The White Company is a likely state-sponsored threat actor with advanced capabilities. From 2017 through 2018, the group led an espionage campaign called Operation Shaheen targeting government and mil
๐Ÿ‡ต๐Ÿ‡ฐ Pakistan 7 techniques 2 software
G0028
Threat Group-1314
TG-1314
Threat Group-1314 is an unattributed threat group that has used compromised credentials to log into a victim's remote access infrastructure.
4 techniques 2 software
G0027
Threat Group-3390
Earth Smilodon, TG-3390, Emissary Panda, BRONZE UNION
Threat Group-3390 is a Chinese threat group that has extensively used strategic Web compromises to target victims. The group has been active since at least 2010 and has targeted organizations in the a
๐Ÿ‡จ๐Ÿ‡ณ China 57 techniques 24 software
G0076
Thrip
Thrip is an espionage group that has targeted satellite communications, telecoms, and defense contractor companies in the U.S. and Southeast Asia. The group uses custom malware as well as "living off
4 techniques 3 software
G1022
ToddyCat
ToddyCat is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets across Europe
25 techniques 9 software
G0131
Tonto Team
Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda
Tonto Team is a suspected Chinese state-sponsored cyber espionage threat group that has primarily targeted South Korea, Japan, Taiwan, and the United States since at least 2009; by 2020 they expanded
๐Ÿ‡จ๐Ÿ‡ณ China 15 techniques 6 software
G0134
Transparent Tribe
COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM
Transparent Tribe is a suspected Pakistan-based threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.
๐Ÿ‡ต๐Ÿ‡ฐ Pakistan 14 techniques 5 software
G0081
Tropic Trooper
Pirate Panda, KeyBoy
Tropic Trooper is an unaffiliated threat group that has led targeted campaigns against targets in Taiwan, the Philippines, and Hong Kong. Tropic Trooper focuses on targeting government, healthcare, tr
40 techniques 6 software
G0010
Turla
IRON HUNTER, Group 88, Waterbug, WhiteBear
Turla is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least 2004, spanning a range of
๐Ÿ‡ท๐Ÿ‡บ Russia 68 techniques 30 software
G1048
UNC3886
UNC3886 is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pac
๐Ÿ‡จ๐Ÿ‡ณ China 49 techniques 8 software
G1047
Velvet Ant
Velvet Ant is a threat actor operating since at least 2021. Velvet Ant is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations, and the use
22 techniques 2 software
G1055
VOID MANTICORE
COBALT MYSTIQUE, Handala Hack, Homeland Justice, Karma
VOID MANTICORE is a threat group assessed to operate on behalf of Iranโ€™s Ministry of Intelligence and Security (MOIS). Active since at least mid-2022, VOID MANTICORE has targeted government entities,
๐Ÿ‡ฎ๐Ÿ‡ท Iran 63 techniques 0 software
G0123
Volatile Cedar
Lebanese Cedar
Volatile Cedar is a Lebanese threat group that has targeted individuals, companies, and institutions worldwide. Volatile Cedar has been operating since 2012 and is motivated by political and ideologic
๐Ÿ‡ฑ๐Ÿ‡ง Lebanon 5 techniques 2 software
G1017
Volt Typhoon
BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territori
๐Ÿ‡จ๐Ÿ‡ณ China 81 techniques 17 software
G1050
Water Galura
GOLD FEATHER
Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russi
๐Ÿ‡ท๐Ÿ‡บ Russia 3 techniques 2 software
G0107
Whitefly
Whitefly is a cyber espionage group that has been operating since at least 2017. The group has targeted organizations based mostly in Singapore across a wide variety of sectors, and is primarily inter
9 techniques 1 software
G0124
Windigo
The Windigo group has been operating since at least 2011, compromising thousands of Linux and Unix servers using the Ebury SSH backdoor to create a spam botnet. Despite law enforcement intervention ag
7 techniques 1 software
G0112
Windshift
Bahamut
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.
19 techniques 1 software
G0044
Winnti Group
Blackfly
Winnti Group is a threat group with Chinese origins that has been active since at least 2010. The group has heavily targeted the gaming industry, but it has also expanded the scope of its targeting. S
๐Ÿ‡จ๐Ÿ‡ณ China 6 techniques 3 software
G1035
Winter Vivern
TA473, UAC-0114
Winter Vivern is a group linked to Russian and Belorussian interests active since at least 2020 targeting various European government and NGO entities, along with sporadic targeting of Indian and US v
๐Ÿ‡ท๐Ÿ‡บ Russia 27 techniques 0 software
G0090
WIRTE
Ashen Lepus
WIRTE is a cyberespionage actor, believed to be a subgroup of the Hamas-affiliated Gaza Cybergang, that has been active since at least August 2018. WIRTE has targeted diplomatic, financial, military,
26 techniques 8 software
G0102
Wizard Spider
UNC1878, TEMP.MixMaster, Grim Spider, FIN12
Wizard Spider is a Russia-based financially motivated threat group originally known for the creation and deployment of TrickBot since at least 2016. Wizard Spider possesses a diverse arsenal of tools
๐Ÿ‡ท๐Ÿ‡บ Russia 64 techniques 22 software
G0128
ZIRCONIUM
APT31, Violet Typhoon
ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the internation
๐Ÿ‡จ๐Ÿ‡ณ China 29 techniques 0 software
โ†‘