>samit_hota

Threat Intelligence

Know your adversary

Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.

176 adversary profiles published

G1050Critical

Water Galura (GOLD FEATHER) Threat Actor Profile

A detailed profile of Water Galura (G1050), also known as GOLD FEATHER or Qilin ransomware, a financially motivated RaaS group.

Jul 19, 2026Russian-speaking
G1055Critical

VOID MANTICORE (G1055): Iran's Destructive Cyber Arm

Profile of VOID MANTICORE, an Iran-backed threat group (G1055) known for destructive wiper and hack-and-leak operations targeting government, critical…

Jul 19, 2026Iran
G0139High

Threat Actor Profile: TeamTNT (G0139)

TeamTNT is a financially motivated threat group known for targeting cloud and containerized environments to deploy cryptocurrency miners and steal credentials.

Jul 18, 2026Germany
G1038High

TA578: A Persistent Initial Access Broker Evolving with New Loaders

TA578 is an active, financially motivated initial access broker known for distributing various malware, primarily targeting organizations in North America and…

Jul 18, 2026
G1037High

TA577: Adaptive Initial Access Broker Evolving to Post-Exploitation

TA577, a Russian-nexus IAB, specializes in global phishing campaigns to deliver malware and steal NTLM hashes, enabling ransomware attacks.

Jul 18, 2026Russia
G0127High

TA551: Persistent Initial Access Broker Fueling Cybercrime

TA551 (GOLD CABIN, Shathak) is a financially-motivated threat group known for high-volume malspam campaigns, acting as an initial access broker for ransomware.

Jul 18, 2026
G0092Critical

TA505 Threat Profile: An Evolving and Persistent Cybercrime Syndicate

A detailed profile of TA505 (G0092), a highly active and financially motivated cybercrime group known for its adaptive TTPs, extensive malware arsenal, and…

Jul 18, 2026Russia or former Soviet states
G0062High

TA459: China-Backed Espionage Group Targeting Eurasian Interests

TA459 is a highly active, China-sponsored APT group focused on long-term intelligence collection against strategic entities in Russia and Central Asia.

Jul 18, 2026China
G1018High

TA2541 Threat Profile: A Persistent Cybercriminal Group

An in-depth profile of TA2541, a cybercriminal group targeting critical industries with high-volume campaigns and commodity RATs.

Jul 18, 2026Eastern Europe
G0039High

Suckfly (G0039): A Profile of China-Based Cyber Espionage

Suckfly is a China-based advanced persistent threat (APT) group active since 2014, primarily targeting government and commercial entities for cyber espionage.

Jul 18, 2026China
G0041High

Strider (ProjectSauron): A Profile of a Sophisticated Cyber Espionage Group

An in-depth profile of Strider (G0041), also known as ProjectSauron, a highly sophisticated, likely nation-state sponsored cyber espionage group.

Jul 18, 2026
G1046High

Storm-1811: Financially Motivated Ransomware Affiliate

Storm-1811 (G1046) is an active, financially motivated threat actor known for sophisticated social engineering, leading to Black Basta ransomware deployment.

Jul 18, 2026