>samit_hota

Threat Intelligence

Know your adversary

Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.

176 adversary profiles published

G0107High

Whitefly (G0107) Threat Profile: Singapore's Persistent Cyber Espionage Adversary

Whitefly (G0107) is a state-sponsored cyber espionage group primarily targeting Singaporean organizations across various sectors to steal sensitive data.

Jul 20, 2026China
G0112High

Windshift (G0112): A Persistent Cyber Espionage Threat

Windshift, also known as Bahamut, is a sophisticated cyber espionage group targeting government and critical infrastructure in the Middle East and South Asia.

Jul 20, 2026Middle East (state-sponsored attribution); also links to Indian territory for "hack-for-hire" operations
G0123High

Volatile Cedar: Persistent Lebanese Cyber Espionage Group (G0123)

Volatile Cedar, an APT group known as Lebanese Cedar, conducts cyber espionage targeting various global sectors for political and ideological motives.

Jul 20, 2026Lebanon
G0124High

Windigo (G0124) Threat Profile: Ebury Botnet Remains Active and Evolving

A detailed profile of Windigo (G0124), a financially motivated threat group known for compromising Linux/Unix servers with the Ebury SSH backdoor.

Jul 20, 2026Russia
G0128High

ZIRCONIUM (G0128): China's Espionage Arm Targeting Global Interests

This profile details ZIRCONIUM (APT31), a Chinese state-sponsored cyber espionage group actively targeting critical sectors and political entities worldwide.

Jul 20, 2026China
G0131High

Tonto Team (G0131): A Decade of Chinese Cyber Espionage

An in-depth look at Tonto Team (G0131), a sophisticated Chinese state-sponsored cyber espionage group targeting critical sectors globally.

Jul 19, 2026China
G0134High

Transparent Tribe (G0134): Persistent Cyber Espionage Targeting India

Transparent Tribe is a Pakistan-based APT group, active since 2013, notorious for cyber espionage and information theft against Indian government, military,…

Jul 19, 2026Pakistan
G1017Critical

Volt Typhoon: PRC's Critical Infrastructure Sabotage Force

Volt Typhoon is a PRC state-sponsored threat actor targeting critical infrastructure in the US and its territories for pre-positioning and potential…

Jul 19, 2026People's Republic of China
G1022High

ToddyCat (G1022): Evolving Cyber Espionage Operations

A profile of ToddyCat (G1022), a sophisticated APT group active since 2020, targeting government/military sectors in Europe/Asia for cyber espionage.

Jul 19, 2026Suspected China
G1035High

Winter Vivern: Relentless Espionage Targeting Europe

Winter Vivern is a pro-Russian cyber espionage group targeting European governments and critical infrastructure with phishing and webmail exploits.

Jul 19, 2026Russia, Belarus
G1047High

Velvet Ant (G1047): China-Nexus Espionage Group with Advanced Persistence

A detailed profile of Velvet Ant (G1047), a China-nexus cyber espionage group known for sophisticated persistence, zero-day exploits, and targeting network…

Jul 19, 2026China-nexus
G1048Critical

UNC3886: China-Nexus Cyber Espionage Targeting Critical Infrastructure

UNC3886 is a highly sophisticated, China-nexus cyber espionage group known for exploiting zero-days in network and virtualization technologies to target…

Jul 19, 2026China