Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
Threat Actor Profile: TeamPCP (UNC6780)
Detailed security profile on TeamPCP (PCPCat/UNC6780), covering their cloud-native CI/CD supply chain attacks and ransomware partnerships.
Threat Actor Profile: ShinyHunters (UNC6240 / Bling Libra)
Deep dive into ShinyHunters (UNC6240), covering their cloud database breaches, social engineering tactics, BreachForums administration, and extortion.
Threat Actor Profile: Turla (G0010)
A detailed analysis of the long-standing Russian state-sponsored APT group Turla, its complex malware ecosystem, and global espionage tactics.
APT27 / Threat Group-3390: Profiling the Emissary Panda Operations
An in-depth look at the tactics, techniques, and operational history of the state-sponsored threat group known as APT27 or Emissary Panda.
Threat Profile: The Modus Operandi of TG-1314 (G0028)
An analytical profile of the threat actor TG-1314, focusing on their reliance on credential exploitation and remote access infrastructure.
Wizard Spider: The Evolution of Russia-Based Ransomware Operations
An in-depth analysis of the prolific Wizard Spider cybercriminal syndicate, their diverse toolset, and their evolution into a major ransomware threat.
Threat Actor Profile: Winnti Group (G0044)
An in-depth analysis of the Winnti Group, a long-standing threat actor focused on intellectual property theft and supply chain compromises.
Threat Profile: Thrip (G0076)
Deep dive into the espionage tactics and "living off the land" methodologies employed by the threat actor group known as Thrip.
Threat Actor Profile: Tropic Trooper (G0081 / KeyBoy)
An in-depth security analysis of Tropic Trooper, a long-standing threat actor focused on intelligence gathering across East and Southeast Asia.
TEMP.Veles: A Persistent and Dangerous Threat to Critical Infrastructure
TEMP.Veles, also known as XENOTIME, is a Russia-based threat group targeting industrial safety systems, known for developing the destructive TRITON malware.
The White Company (G0089): A State-Sponsored Espionage Threat
The White Company (G0089) is a state-sponsored threat actor with advanced capabilities, primarily focused on espionage against government and military targets.
WIRTE (Ashen Lepus): Persistent Hamas-Affiliated Cyber Espionage Actor
A detailed profile of WIRTE (G0090), a Hamas-affiliated cyber espionage actor known for targeting Middle Eastern entities with evolving malware and TTPs.
No adversaries match your search.