Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
APT-C-23 (Arid Viper): Persistent Cyber Espionage in the Middle East
APT-C-23, also known as Arid Viper, is a sophisticated, likely state-sponsored group primarily targeting the Middle East with advanced mobile and Windows…
North Korea-linked AppleJeus: A Profile of G1049, a State-Sponsored Cybercrime Group
AppleJeus (G1049) is a North Korean state-sponsored threat group primarily focused on financial gain through sophisticated cryptocurrency theft and supply…
Aoqin Dragon: Persistent Cyber Espionage Targeting APAC
A profile of Aoqin Dragon (G1007), a suspected Chinese cyber espionage group actively targeting government, education, and telecom entities since 2013.
Andariel (G0138): North Korea's Dual-Threat Cyber Espionage and Ransomware Group
A profile of Andariel (G0138), a North Korean state-sponsored threat group known for cyber espionage, destructive attacks, and financially motivated…
Akira Ransomware: A Persistent and Evolving Global Threat
Akira is a financially motivated ransomware-as-a-service (RaaS) group employing double extortion tactics against diverse sectors worldwide.
Ajax Security Team (G0130): An Iranian Cyber Espionage Group
An in-depth profile of the Iranian-nexus threat actor known as Ajax Security Team (G0130) or Rocket Kitten, detailing their origins, motivations, targets,…
Agrius (G1030): Iran's Destructive Cyber Arm Targeting Israel
Agrius (G1030), an Iranian state-sponsored APT, specializes in destructive wiper and pseudo-ransomware attacks, primarily targeting Israeli sectors since 2020.
Threat Actor Profile: admin@338 (G0018)
In-depth profile of admin@338, a China-based threat group known for cyber espionage against financial, economic, and media organizations.
No adversaries match your search.