Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
BlackByte Ransomware: A Persistent Double Extortion Threat
Profile of BlackByte (G1043), a ransomware-as-a-service (RaaS) group active since 2021, known for double extortion and targeting critical infrastructure…
BITTER (G1002): An Enduring South Asian Cyber Espionage Threat
A detailed profile of BITTER (G1002), a persistent South Asian cyber espionage group, outlining their origins, motivations, targets, TTPs, and current…
BackdoorDiplomacy (G0135) Threat Profile: Persistent Chinese Cyber Espionage
A detailed threat profile of BackdoorDiplomacy, a China-linked APT group known for cyber espionage against diplomatic and telecommunication targets.
Axiom (G0001): Profile of a Sophisticated Chinese Cyber Espionage Group
A detailed profile of Axiom (G0001), a sophisticated, state-sponsored Chinese cyber espionage group targeting high-value intellectual property and sensitive…
Aquatic Panda (G0143) Threat Profile: Persistent Cyber Espionage Operations
Aquatic Panda (G0143) is a China-linked APT conducting intelligence collection and industrial espionage, targeting diverse global sectors with advanced…
APT5 (Mulberry Typhoon): Profile of a Sophisticated China-Based Espionage Actor
APT5, also known as Mulberry Typhoon, is a China-based state-sponsored cyber espionage group targeting telecommunications, aerospace, and defense sectors…
APT42: Iran's Premier Human-Targeting Cyber Espionage Unit
Iranian state-sponsored APT42 conducts cyber espionage and surveillance, primarily using sophisticated social engineering and credential harvesting to target…
APT41: China's Dual-Threat Cyber Powerhouse
APT41 is a prolific Chinese state-sponsored threat group notorious for blending sophisticated cyber espionage with financially motivated operations globally.
APT39: Iran's Relentless Surveillance Threat
APT39, also known as Chafer and Remix Kitten, is an Iranian state-sponsored cyber espionage group focused on collecting personal information for surveillance.
APT38: North Korea's Relentless Financial Cyber Offensive
Profile of APT38, a North Korean state-sponsored threat group specializing in global financial cyber operations, destructive attacks, and cryptocurrency theft.
APT37 (ScarCruft): North Korea's Evolving Cyber Espionage Group
APT37, a North Korean state-sponsored cyber espionage group, targets South Korea and global entities with sophisticated tactics and diverse custom malware.
APT33: Iran's Evolving Cyber Espionage and Destructive Capabilities
A detailed profile of APT33 (G0064), an Iranian state-sponsored threat group known for cyber espionage against critical infrastructure and a recent shift to…
No adversaries match your search.