Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
Water Galura (GOLD FEATHER) Threat Actor Profile
A detailed profile of Water Galura (G1050), also known as GOLD FEATHER or Qilin ransomware, a financially motivated RaaS group.
VOID MANTICORE (G1055): Iran's Destructive Cyber Arm
Profile of VOID MANTICORE, an Iran-backed threat group (G1055) known for destructive wiper and hack-and-leak operations targeting government, critical…
Threat Actor Profile: TeamTNT (G0139)
TeamTNT is a financially motivated threat group known for targeting cloud and containerized environments to deploy cryptocurrency miners and steal credentials.
TA578: A Persistent Initial Access Broker Evolving with New Loaders
TA578 is an active, financially motivated initial access broker known for distributing various malware, primarily targeting organizations in North America and…
TA577: Adaptive Initial Access Broker Evolving to Post-Exploitation
TA577, a Russian-nexus IAB, specializes in global phishing campaigns to deliver malware and steal NTLM hashes, enabling ransomware attacks.
TA551: Persistent Initial Access Broker Fueling Cybercrime
TA551 (GOLD CABIN, Shathak) is a financially-motivated threat group known for high-volume malspam campaigns, acting as an initial access broker for ransomware.
TA505 Threat Profile: An Evolving and Persistent Cybercrime Syndicate
A detailed profile of TA505 (G0092), a highly active and financially motivated cybercrime group known for its adaptive TTPs, extensive malware arsenal, and…
TA459: China-Backed Espionage Group Targeting Eurasian Interests
TA459 is a highly active, China-sponsored APT group focused on long-term intelligence collection against strategic entities in Russia and Central Asia.
TA2541 Threat Profile: A Persistent Cybercriminal Group
An in-depth profile of TA2541, a cybercriminal group targeting critical industries with high-volume campaigns and commodity RATs.
Suckfly (G0039): A Profile of China-Based Cyber Espionage
Suckfly is a China-based advanced persistent threat (APT) group active since 2014, primarily targeting government and commercial entities for cyber espionage.
Strider (ProjectSauron): A Profile of a Sophisticated Cyber Espionage Group
An in-depth profile of Strider (G0041), also known as ProjectSauron, a highly sophisticated, likely nation-state sponsored cyber espionage group.
Storm-1811: Financially Motivated Ransomware Affiliate
Storm-1811 (G1046) is an active, financially motivated threat actor known for sophisticated social engineering, leading to Black Basta ransomware deployment.
No adversaries match your search.