Threat Groups
Threat actors tracked across all RSS feeds — nation-states, ransomware gangs, and hacktivists
Nation-State Nation-State Groups
Russian FSB-linked group conducting targeted spear-phishing against NGOs, journalists, and academic …
Russian military intelligence (GRU) hacking group active since mid-2000s. Known for targeting NATO g…
North Korean state-sponsored group linked to the Reconnaissance General Bureau. Responsible for majo…
GRU Unit 74455 responsible for destructive attacks including NotPetya, attacks on Ukrainian power gr…
Iranian MOIS-linked group targeting telecommunications, government, and defense sectors across the M…
Russian FSB group known for sophisticated cyber-espionage campaigns targeting governments, embassies…
North Korean APT group focused on intelligence gathering, targeting South Korean government, think t…
Russian FSB-linked group almost exclusively targeting Ukrainian government, military, and critical i…
Russian Foreign Intelligence Service (SVR) group known for sophisticated long-term intrusions into g…
Chinese state-sponsored group conducting both espionage and financially motivated cybercrime. Known …
Iranian IRGC-linked group conducting phishing and credential theft against journalists, academics, h…
Chinese state-sponsored group focused on critical infrastructure targeting, particularly US military…
Chinese threat actor responsible for major breaches of US telecommunications providers, targeting wi…
Chinese state-sponsored group targeting Taiwanese organizations and critical infrastructure sectors …
Chinese APT group targeting Southeast Asian governments, NGOs, and minorities using PlugX malware.
Vietnamese state-sponsored group conducting espionage against foreign governments, dissidents, and j…
Suspected Indian state-sponsored group targeting military and government organizations in Pakistan, …
Chinese APT group targeting tech, media, and telecommunications companies in East Asia, particularly…
Sophisticated Chinese espionage group targeting VMware ESXi hypervisors and network edge devices wit…
North Korean-linked group responsible for the 3CX supply chain attack in 2023.
Russian GRU-linked group conducting destructive attacks against Ukrainian targets, associated with W…
Cybercriminal Cybercriminal Groups
English-speaking cybercriminal group known for sophisticated social engineering, SIM swapping, and r…
Prolific financially motivated group known for targeting retail, hospitality, and restaurant sectors…
Financially motivated group known for large-scale phishing campaigns and deployment of Clop ransomwa…
Prolific threat actor operating large-scale malware distribution campaigns including Dridex and Clop…
Cybercriminal group known for high-volume phishing campaigns distributing QakBot and other malware.
Threat actor operating SocGholish (FakeUpdates) malware distribution network through compromised web…
Russian-speaking cybercriminal group operating TrickBot and Conti ransomware. Known for targeting ho…
Operators of the LockBit ransomware-as-a-service platform, one of the most prolific ransomware group…
Operators of the ALPHV/BlackCat ransomware, responsible for major attacks including Change Healthcar…
Cybercriminal group behind the Clop ransomware, known for mass exploitation of zero-day vulnerabilit…
Russian ransomware-as-a-service operation responsible for attacks on Kaseya, JBS Foods, and Travelex…
Ransomware group responsible for the Colonial Pipeline attack in 2021, causing widespread fuel short…
Ransomware group that emerged in 2023, targeting healthcare, education, and government sectors. Know…
Ransomware-as-a-service operation active since 2023, targeting SMBs across multiple sectors with dou…
Ransomware group targeting enterprise networks, known for exploiting Exchange vulnerabilities and us…
Ransomware group that shifted from encryption-based to pure extortion model, targeting healthcare, p…
Ransomware group known for maintaining a public Telegram channel to pressure victims and publish sto…
Ransomware group that surged in activity in 2023, targeting SMBs with Phobos ransomware and operatin…
Ransomware group that appeared in late 2023, believed to be a rebranded or spin-off of the Hive rans…
Group conducting ransom DDoS (RDoS) campaigns threatening organizations with DDoS attacks unless ran…
Russian cybercriminal organization led by Maksim Yakubets, responsible for Dridex banking trojan and…
Hacktivist Hacktivist Groups
Pro-Russian hacktivist group conducting DDoS attacks against Ukraine and Western governments support…
Hacktivist group conducting large-scale DDoS attacks, suspected of ties to Russian interests despite…
Pro-Russian hacktivist group conducting DDoS attacks against governments and organizations supportin…