Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
Storm-0501: An Evolving Hybrid Cloud Ransomware Threat
Storm-0501, a financially motivated group active since 2021, has evolved from traditional ransomware to sophisticated hybrid and cloud-native attacks.
Stealth Falcon: A Persistent Espionage Threat
Stealth Falcon (G0038) is an active APT group, linked to the UAE government, conducting cyber espionage against targets in the Middle East and Africa.
Star Blizzard: Russia's Persistent Cyber Espionage Engine
Star Blizzard, a highly active Russian state-sponsored cyber espionage group, employs sophisticated spear-phishing and social engineering to target critical…
Sowbug (G0054) Threat Profile: Cyber Espionage in South America & Southeast Asia
Sowbug (G0054) is a sophisticated cyber espionage group targeting government entities in South America and Southeast Asia, active since at least 2015.
Nigerian BEC Syndicate: SilverTerrier (G0083) Threat Profile
A detailed security profile of SilverTerrier (G0083), a Nigerian cybercrime group specializing in sophisticated Business Email Compromise (BEC) scams.
Silent Librarian: Iran's Relentless Academic Espionage Arm
Silent Librarian (G0122) is an Iranian state-sponsored APT group focused on intellectual property theft from academic and research institutions worldwide.
Silence (G0091): A Persistent Financial Threat to Global Banking
Profile of Silence (G0091), a financially motivated threat actor targeting financial institutions worldwide with sophisticated tactics.
Sidewinder (G0121): Agile Cyber-Espionage Targeting Critical Sectors
SideWinder is a sophisticated, India-linked APT group active since 2012, primarily conducting cyber-espionage against South Asian governmental, military, and…
Scarlet Mimic (G0029): Persistent Cyber Espionage Against Activists
Scarlet Mimic is an espionage threat group known for targeting minority rights activists and related government entities, notably using custom malware for…
Salt Typhoon (G1045): Persistent PRC State-Backed Espionage Threat
Salt Typhoon (G1045) is a highly sophisticated, PRC state-backed APT group conducting extensive cyber espionage and pre-positioning in global critical…
SideCopy Threat Actor Profile: Persistent Espionage in South Asia
A detailed security professional's profile of SideCopy (G1008), a Pakistan-linked threat group known for persistent cyber espionage against South Asian…
Sea Turtle (G1041): Persistent State-Aligned Espionage
Profile of Sea Turtle (G1041), a Türkiye-linked APT focused on espionage via DNS hijacking, vulnerability exploitation, and cloud compromise.
No adversaries match your search.