>samit_hota

Threat Intelligence

Know your adversary

Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.

176 adversary profiles published

G1053High

Storm-0501: An Evolving Hybrid Cloud Ransomware Threat

Storm-0501, a financially motivated group active since 2021, has evolved from traditional ransomware to sophisticated hybrid and cloud-native attacks.

Jul 18, 2026
G0038High

Stealth Falcon: A Persistent Espionage Threat

Stealth Falcon (G0038) is an active APT group, linked to the UAE government, conducting cyber espionage against targets in the Middle East and Africa.

Jul 18, 2026United Arab Emirates (suspected)
G1033High

Star Blizzard: Russia's Persistent Cyber Espionage Engine

Star Blizzard, a highly active Russian state-sponsored cyber espionage group, employs sophisticated spear-phishing and social engineering to target critical…

Jul 18, 2026Russia
G0054High

Sowbug (G0054) Threat Profile: Cyber Espionage in South America & Southeast Asia

Sowbug (G0054) is a sophisticated cyber espionage group targeting government entities in South America and Southeast Asia, active since at least 2015.

Jul 18, 2026
G0083High

Nigerian BEC Syndicate: SilverTerrier (G0083) Threat Profile

A detailed security profile of SilverTerrier (G0083), a Nigerian cybercrime group specializing in sophisticated Business Email Compromise (BEC) scams.

Jul 18, 2026Nigeria
G0122High

Silent Librarian: Iran's Relentless Academic Espionage Arm

Silent Librarian (G0122) is an Iranian state-sponsored APT group focused on intellectual property theft from academic and research institutions worldwide.

Jul 18, 2026Iran
G0091High

Silence (G0091): A Persistent Financial Threat to Global Banking

Profile of Silence (G0091), a financially motivated threat actor targeting financial institutions worldwide with sophisticated tactics.

Jul 18, 2026Russia/Eastern Europe
G0121High

Sidewinder (G0121): Agile Cyber-Espionage Targeting Critical Sectors

SideWinder is a sophisticated, India-linked APT group active since 2012, primarily conducting cyber-espionage against South Asian governmental, military, and…

Jul 18, 2026India (suspected)
G0029High

Scarlet Mimic (G0029): Persistent Cyber Espionage Against Activists

Scarlet Mimic is an espionage threat group known for targeting minority rights activists and related government entities, notably using custom malware for…

Jul 18, 2026East Asia
G1045Critical

Salt Typhoon (G1045): Persistent PRC State-Backed Espionage Threat

Salt Typhoon (G1045) is a highly sophisticated, PRC state-backed APT group conducting extensive cyber espionage and pre-positioning in global critical…

Jul 17, 2026People's Republic of China (PRC)
G1008High

SideCopy Threat Actor Profile: Persistent Espionage in South Asia

A detailed security professional's profile of SideCopy (G1008), a Pakistan-linked threat group known for persistent cyber espionage against South Asian…

Jul 17, 2026Pakistan
G1041High

Sea Turtle (G1041): Persistent State-Aligned Espionage

Profile of Sea Turtle (G1041), a Türkiye-linked APT focused on espionage via DNS hijacking, vulnerability exploitation, and cloud compromise.

Jul 17, 2026Turkey