>samit_hota

Threat Intelligence

Know your adversary

Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.

176 adversary profiles published

G0117High

Fox Kitten: An Iranian Hybrid Threat Actor

Fox Kitten (G0117) is an Iranian state-sponsored threat actor active since 2017, engaged in espionage and ransomware facilitation.

Jul 14, 2026Iran
G0061High

FIN8: Adapting from POS Breaches to Ransomware Dominance

FIN8, also known as Syssphinx, is a financially motivated cybercrime group that has evolved from targeting POS systems to deploying sophisticated ransomware…

Jul 14, 2026Commonwealth of Independent States (CIS) region
G0046High

FIN7: From Point-of-Sale Theft to Ransomware Kingpins

A deep dive into FIN7, a financially motivated cybercrime group known for evolving from POS attacks to sophisticated ransomware operations.

Jul 14, 2026Eastern Europe
G0037High

FIN6: From POS Skimming to Ransomware and Enterprise Infiltration

A detailed profile of FIN6 (G0037), a financially motivated cybercrime group known for evolving from PoS compromises to ransomware and sophisticated social…

Jul 14, 2026Eastern Europe
G0053High

FIN5 Threat Actor Profile: Persistent Point-of-Sale Scraper

A profile of FIN5 (G0053), a financially motivated threat group known for targeting hospitality, gaming, and restaurant sectors for payment card data.

Jul 14, 2026Eastern Europe (likely Russian-speaking)
G0085High

FIN4: The Insider Threat to Market Confidentiality

FIN4 is a financially-motivated threat group focused on stealing market-moving confidential information, primarily through credential theft and email…

Jul 14, 2026
G1016High

FIN13 (Elephant Beetle): Mexico-Focused Financial Threat Group

FIN13, also known as Elephant Beetle, is a patient, financially motivated threat actor primarily targeting Mexico and Latin America's financial, retail, and…

Jul 14, 2026
G0051Medium

FIN10: The North American Extortionist Cybercrime Group

Profile of FIN10 (G0051), a financially motivated threat group that operated in North America, primarily Canada, known for data exfiltration and extortion of…

Jul 14, 2026
G1011High

EXOTIC LILY: Premier Initial Access Broker Fueling Ransomware Operations

EXOTIC LILY (G1011) is a financially motivated initial access broker known for sophisticated spear phishing campaigns and ties to Russian cybercrime.

Jul 14, 2026Europe (likely Central or Eastern Europe), closely linked to Russian cybercrime group WIZARD SPIDER.
G0120High

Evilnum (G0120): Persistent Financial Threat and Evolving Espionage Actor

Evilnum (G0120) is a financially motivated threat group active since 2018, primarily targeting financial technology companies and other entities for extensive…

Jul 14, 2026
G0020Critical

Equation: Apex Predator of Cyber Espionage

A profile of the Equation Group, a highly sophisticated threat actor widely attributed to the NSA, known for zero-days, firmware exploits, and deep cyber…

Jul 14, 2026United States
G1003Critical

Ember Bear (G1003): Russian Cyber Espionage and Destructive Operations

Profile of Ember Bear (G1003), a Russian state-sponsored cyber espionage group linked to GRU Unit 29155, detailing their origins, motivations, targets, TTPs,…

Jul 14, 2026Russia