onlinesyscfg.research
utc
syscfg://research
cat /etc/threat-actors.db

Threat Groups

12 tracked threat actors - nation-state APTs, ransomware operators, financial theft groups. Click any entry for TTPs, known operations, and attribution.

5 espionage3 ransomware1 financial3 hybrid·9 active3 disrupted
/
🇷🇺
APT29 / Cozy BearespionageActive
Russia (SVR) · since 2008

Russia's Foreign Intelligence Service (SVR) cyber unit, responsible for the SolarWinds SUNBURST supply chain attack, the...

Midnight BlizzardNOBELIUM+1 more
🇷🇺
APT28 / Fancy BearespionageActive
Russia (GRU Unit 26165) · since 2004

GRU military intelligence unit responsible for DNC breach, French election interference, WADA breach, and NATO targeting...

Forest BlizzardSTRONTIUM+2 more
🇷🇺
SandwormhybridActive
Russia (GRU Unit 74455) · since 2009

GRU destructive operations unit responsible for the most damaging cyberattacks in history: NotPetya ($10B+ damage), Ukra...

Voodoo BearELECTRUM+2 more
🇨🇳
Volt TyphoonespionageActive
China (PRC) · since 2021

Pre-positioning campaign targeting US critical infrastructure - power grids, water systems, communications, and transpor...

Bronze SilhouetteVanguard Panda
🇨🇳
Salt TyphoonespionageActive
China (MSS) · since 2019

Telecom-focused espionage group that breached AT&T, Verizon, T-Mobile, and dozens of other carriers worldwide, accessing...

Earth EstriesGhostEmperor+1 more
🇨🇳
APT41 / Double DragonhybridActive
China (MSS) · since 2012

Dual-purpose group conducting both state-sponsored espionage and financially-motivated cybercrime. Targets government an...

WinntiBarium+1 more
🇰🇵
Lazarus GroupfinancialActive
North Korea (RGB) · since 2009

North Korea's primary cyber unit conducting financial theft to fund the regime's weapons programs. Responsible for $3B+ ...

Hidden CobraZINC+2 more
🇮🇷
APT33 / ElfinespionageActive
Iran (IRGC) · since 2013

Iranian IRGC unit focused on aerospace, defense, and petrochemical sectors in Saudi Arabia, United States, and South Kor...

Peach SandstormRefined Kitten+1 more
🇮🇷
APT35 / Charming KittenhybridActive
Iran (IRGC) · since 2014

Iranian intelligence unit conducting social engineering-heavy operations against journalists, academics, human rights de...

Mint SandstormPhosphorus+1 more
🦹
ALPHV / BlackCatransomwareDisrupted
Criminal (Russia-linked) · since 2021

Sophisticated ransomware-as-a-service written in Rust. Responsible for Change Healthcare, MGM Resorts (as affiliate), an...

Noberus
🦹
LockBitransomwareDisrupted
Criminal (Russia-based) · since 2019

Most prolific ransomware group 2022-2024 by victim count. Built a professional affiliate model with 24/7 support and cle...

LockBit 3.0LockBit Black+1 more
🕸
Scattered Spider / COMransomwareDisrupted
Criminal (US/UK-based, young adults) · since 2022

English-speaking criminal network of young hackers using sophisticated social engineering against enterprise IT helpdesk...

UNC3944Octo Tempest+1 more