Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
Ferocious Kitten: Persistent Iranian Cyberespionage
A profile of Ferocious Kitten (G0137), an Iranian cyberespionage group targeting Persian-speaking individuals, active since at least 2015.
Threat Actor Profile: Elderwood (G0066)
An in-depth profile of Elderwood (G0066), a sophisticated suspected Chinese cyber espionage group known for zero-day exploits and supply chain attacks.
Earth Lusca (G1006): Persistent and Evolving Threat Profile
A detailed profile of Earth Lusca, a China-linked APT group known for cyberespionage and financially motivated attacks across diverse global targets.
DragonOK: China-Linked APT Group Targeting Asian & European Organizations
DragonOK (G0017) is a China-linked APT group known for corporate espionage against high-tech and manufacturing firms, primarily in Japan.
Threat Actor Profile: Dragonfly (G0035) – Russia’s Critical Infrastructure Espionage Group
An in-depth profile of Dragonfly (G0035), a Russian state-sponsored cyber espionage group targeting global critical infrastructure.
Deep Panda (G0009) Threat Actor Profile: A Persistent Chinese Espionage Group
A profile of Deep Panda (G0009), a sophisticated China-aligned threat group known for cyber espionage and credential theft.
DarkVishnya (G0105) Threat Actor Profile
DarkVishnya is a financially motivated threat actor known for physically breaching Eastern European financial institutions using stealthy hardware.
DarkHydrus: Persistent Middle Eastern Espionage Group
DarkHydrus (G0079) is a state-sponsored threat group primarily targeting government and educational institutions in the Middle East for cyber espionage.
Darkhotel: An Enduring Cyber Espionage Threat
Darkhotel is a sophisticated, suspected South Korean cyber espionage group known for evolving from hotel Wi-Fi attacks to advanced cloud-based operations.
Dark Caracal (G0070) Threat Profile: Mobile-Focused Espionage
Dark Caracal is a state-aligned threat group (G0070) attributed to Lebanese security services, focusing on global mobile and desktop surveillance for espionage.
Daggerfly (G1034): An Adaptive PRC-Linked Espionage Group
This profile details Daggerfly (G1034), a sophisticated China-linked APT group engaged in long-term cyber espionage against diverse targets across Asia and…
CURIUM: Patient Iranian Espionage Group
An Iranian state-sponsored threat actor, CURIUM (G1012), known for its patient social engineering and espionage against Middle Eastern IT service providers.
No adversaries match your search.