Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
Whitefly (G0107) Threat Profile: Singapore's Persistent Cyber Espionage Adversary
Whitefly (G0107) is a state-sponsored cyber espionage group primarily targeting Singaporean organizations across various sectors to steal sensitive data.
Windshift (G0112): A Persistent Cyber Espionage Threat
Windshift, also known as Bahamut, is a sophisticated cyber espionage group targeting government and critical infrastructure in the Middle East and South Asia.
Volatile Cedar: Persistent Lebanese Cyber Espionage Group (G0123)
Volatile Cedar, an APT group known as Lebanese Cedar, conducts cyber espionage targeting various global sectors for political and ideological motives.
Windigo (G0124) Threat Profile: Ebury Botnet Remains Active and Evolving
A detailed profile of Windigo (G0124), a financially motivated threat group known for compromising Linux/Unix servers with the Ebury SSH backdoor.
ZIRCONIUM (G0128): China's Espionage Arm Targeting Global Interests
This profile details ZIRCONIUM (APT31), a Chinese state-sponsored cyber espionage group actively targeting critical sectors and political entities worldwide.
Tonto Team (G0131): A Decade of Chinese Cyber Espionage
An in-depth look at Tonto Team (G0131), a sophisticated Chinese state-sponsored cyber espionage group targeting critical sectors globally.
Transparent Tribe (G0134): Persistent Cyber Espionage Targeting India
Transparent Tribe is a Pakistan-based APT group, active since 2013, notorious for cyber espionage and information theft against Indian government, military,…
Volt Typhoon: PRC's Critical Infrastructure Sabotage Force
Volt Typhoon is a PRC state-sponsored threat actor targeting critical infrastructure in the US and its territories for pre-positioning and potential…
ToddyCat (G1022): Evolving Cyber Espionage Operations
A profile of ToddyCat (G1022), a sophisticated APT group active since 2020, targeting government/military sectors in Europe/Asia for cyber espionage.
Winter Vivern: Relentless Espionage Targeting Europe
Winter Vivern is a pro-Russian cyber espionage group targeting European governments and critical infrastructure with phishing and webmail exploits.
Velvet Ant (G1047): China-Nexus Espionage Group with Advanced Persistence
A detailed profile of Velvet Ant (G1047), a China-nexus cyber espionage group known for sophisticated persistence, zero-day exploits, and targeting network…
UNC3886: China-Nexus Cyber Espionage Targeting Critical Infrastructure
UNC3886 is a highly sophisticated, China-nexus cyber espionage group known for exploiting zero-days in network and virtualization technologies to target…
No adversaries match your search.