130
Most Prolific Actor
51
Most Deployed Malware
Mimikatz
55
Groups Referencing CVEs
31% of all groups
65
Unattributed Groups
No confirmed origin
Tactic Prevalence
Phishing Observed
98 groups
56% of groups use phishing-based initial access techniques.
Defence Evasion
150 groups
85% of groups employ defence evasion tactics.
Credential Access
96 groups
55% of groups target credential stores or authentication data.
Command & Control
130 groups
74% of groups establish a command and control channel.
Persistence
123 groups
70% of groups establish persistence mechanisms on targeted systems.
Discovery
113 groups
64% of groups conduct active discovery activity post-compromise.
Actor Intelligence
Sophisticated Actors
84
Groups with 20 or more documented techniques. Represents 48% of all tracked groups.
Average Technique Coverage
26.3
Mean number of unique techniques documented per threat group across all 176 groups.
Top Attributed Nation
🇨🇳 China
47 groups attributed to China in public reporting.
View details ↗
Most Targeted Sector
Government
69 groups have been observed targeting the Government sector.
View details ↗
CVE Referencing Groups
31%
55 of 176 groups have CVEs referenced within their intelligence profiles.
Attribution Gap
37%
65 groups have no confirmed nation-state origin in public reporting.
View details ↗
Tactic Prevalence by Group Count
How many groups use each kill-chain tactic
Stealth
149
Execution
148
Initial Access
145
Command & Control
130
Persistence
123
Privilege Escalation
120
Resource Development
117
Discovery
113
Credential Access
96
Collection
94
Defence Impairment
79
Lateral Movement
78
Exfiltration
59
Reconnaissance
48
Impact
38
Top 10 Techniques by Group Coverage
Most widely observed individual techniques
T1105 Ingress Tool T
88
T1204.002 Malicious Fi
86
T1059.001 PowerShell
85
T1588.002 Tool
82
T1566.001 Spearphishin
78
T1059.003 Windows Comm
73
T1036.005 Match Legiti
63
T1082 System Informa
58
T1071.001 Web Protocol
57
T1547.001 Registry Run
57
↑