Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
Fox Kitten: An Iranian Hybrid Threat Actor
Fox Kitten (G0117) is an Iranian state-sponsored threat actor active since 2017, engaged in espionage and ransomware facilitation.
FIN8: Adapting from POS Breaches to Ransomware Dominance
FIN8, also known as Syssphinx, is a financially motivated cybercrime group that has evolved from targeting POS systems to deploying sophisticated ransomware…
FIN7: From Point-of-Sale Theft to Ransomware Kingpins
A deep dive into FIN7, a financially motivated cybercrime group known for evolving from POS attacks to sophisticated ransomware operations.
FIN6: From POS Skimming to Ransomware and Enterprise Infiltration
A detailed profile of FIN6 (G0037), a financially motivated cybercrime group known for evolving from PoS compromises to ransomware and sophisticated social…
FIN5 Threat Actor Profile: Persistent Point-of-Sale Scraper
A profile of FIN5 (G0053), a financially motivated threat group known for targeting hospitality, gaming, and restaurant sectors for payment card data.
FIN4: The Insider Threat to Market Confidentiality
FIN4 is a financially-motivated threat group focused on stealing market-moving confidential information, primarily through credential theft and email…
FIN13 (Elephant Beetle): Mexico-Focused Financial Threat Group
FIN13, also known as Elephant Beetle, is a patient, financially motivated threat actor primarily targeting Mexico and Latin America's financial, retail, and…
FIN10: The North American Extortionist Cybercrime Group
Profile of FIN10 (G0051), a financially motivated threat group that operated in North America, primarily Canada, known for data exfiltration and extortion of…
EXOTIC LILY: Premier Initial Access Broker Fueling Ransomware Operations
EXOTIC LILY (G1011) is a financially motivated initial access broker known for sophisticated spear phishing campaigns and ties to Russian cybercrime.
Evilnum (G0120): Persistent Financial Threat and Evolving Espionage Actor
Evilnum (G0120) is a financially motivated threat group active since 2018, primarily targeting financial technology companies and other entities for extensive…
Equation: Apex Predator of Cyber Espionage
A profile of the Equation Group, a highly sophisticated threat actor widely attributed to the NSA, known for zero-days, firmware exploits, and deep cyber…
Ember Bear (G1003): Russian Cyber Espionage and Destructive Operations
Profile of Ember Bear (G1003), a Russian state-sponsored cyber espionage group linked to GRU Unit 29155, detailing their origins, motivations, targets, TTPs,…
No adversaries match your search.