Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
Scattered Spider: Masters of Deception and Identity Abuse
Scattered Spider is a financially motivated, native English-speaking cybercriminal group known for sophisticated social engineering, identity-based attacks,…
Rocke (G0106): Evolution of a Persistent Cryptojacking Adversary
Profile of Rocke (G0106), a Chinese-speaking threat actor focused on cryptojacking, its evolving tactics, tools, and persistent operations.
RedCurl: Espionage Evolving, Ransomware Emerging
RedCurl (G1039) is a Russian-speaking threat actor initially focused on corporate espionage, recently evolving to deploy novel QWCrypt ransomware in targeted…
Sandworm Team (G0034) Threat Profile: Russia's Destructive Cyber Arm
A deep dive into Sandworm Team (APT44), a highly destructive Russian GRU-backed cyber threat actor known for targeting critical infrastructure and global…
Saint Bear (G1031): Russian-Nexus Threat Actor Profile
Saint Bear (G1031) is a Russian-nexus threat actor active since early 2021, primarily conducting cyber espionage against Ukraine and Georgia using custom…
RTM (G0048): A Financially Motivated Cybercriminal Evolution
RTM is a long-standing cybercriminal group, initially focused on banking Trojans, that has evolved into a Ransomware-as-a-Service provider, targeting…
RedEcho: China-Linked Threat Actor Targeting Indian Critical Infrastructure
An in-depth profile of RedEcho (G1042), a China-linked threat actor primarily targeting Indian critical infrastructure, particularly the power sector, for…
Rancor: Persistent Espionage in Southeast Asia
Rancor (G0075) is a China-linked cyber espionage group targeting government and political entities in Southeast Asia since 2017, employing evolving custom…
Poseidon Group: The Extortion-as-a-Service Cyber Mercenaries
A profile of the Poseidon Group (G0033), a Brazilian cyber mercenary gang known for its unique data exfiltration and extortion model.
Play Ransomware (G1040) Threat Profile: Evolving Tactics and Global Impact
A detailed security professional's analysis of the Play ransomware group (G1040), its evolving tactics, global targeting, and current active status.
Putter Panda: Persistent Chinese Cyber Espionage
A detailed profile of Putter Panda (G0024), a Chinese state-sponsored threat group linked to the PLA's Unit 61486, focusing on its espionage motivations,…
PROMETHIUM (StrongPity): A Resilient Espionage Threat
Profile of PROMETHIUM (StrongPity), an espionage-focused APT group active since 2012, known for using trojanized software to target diverse regions and sectors.
No adversaries match your search.