Threat Groups
12 tracked threat actors - nation-state APTs, ransomware operators, financial theft groups. Click any entry for TTPs, known operations, and attribution.
Russia's Foreign Intelligence Service (SVR) cyber unit, responsible for the SolarWinds SUNBURST supply chain attack, the...
GRU military intelligence unit responsible for DNC breach, French election interference, WADA breach, and NATO targeting...
GRU destructive operations unit responsible for the most damaging cyberattacks in history: NotPetya ($10B+ damage), Ukra...
Pre-positioning campaign targeting US critical infrastructure - power grids, water systems, communications, and transpor...
Telecom-focused espionage group that breached AT&T, Verizon, T-Mobile, and dozens of other carriers worldwide, accessing...
Dual-purpose group conducting both state-sponsored espionage and financially-motivated cybercrime. Targets government an...
North Korea's primary cyber unit conducting financial theft to fund the regime's weapons programs. Responsible for $3B+ ...
Iranian IRGC unit focused on aerospace, defense, and petrochemical sectors in Saudi Arabia, United States, and South Kor...
Iranian intelligence unit conducting social engineering-heavy operations against journalists, academics, human rights de...
Sophisticated ransomware-as-a-service written in Rust. Responsible for Change Healthcare, MGM Resorts (as affiliate), an...
Most prolific ransomware group 2022-2024 by victim count. Built a professional affiliate model with 24/7 support and cle...
English-speaking criminal network of young hackers using sophisticated social engineering against enterprise IT helpdesk...