>samit_hota

Threat Intelligence

Know your adversary

Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.

176 adversary profiles published

G1015High

Scattered Spider: Masters of Deception and Identity Abuse

Scattered Spider is a financially motivated, native English-speaking cybercriminal group known for sophisticated social engineering, identity-based attacks,…

Jul 17, 2026United States and United Kingdom
G0106High

Rocke (G0106): Evolution of a Persistent Cryptojacking Adversary

Profile of Rocke (G0106), a Chinese-speaking threat actor focused on cryptojacking, its evolving tactics, tools, and persistent operations.

Jul 17, 2026China
G1039High

RedCurl: Espionage Evolving, Ransomware Emerging

RedCurl (G1039) is a Russian-speaking threat actor initially focused on corporate espionage, recently evolving to deploy novel QWCrypt ransomware in targeted…

Jul 17, 2026Russia
G0034Critical

Sandworm Team (G0034) Threat Profile: Russia's Destructive Cyber Arm

A deep dive into Sandworm Team (APT44), a highly destructive Russian GRU-backed cyber threat actor known for targeting critical infrastructure and global…

Jul 17, 2026Russia
G1031High

Saint Bear (G1031): Russian-Nexus Threat Actor Profile

Saint Bear (G1031) is a Russian-nexus threat actor active since early 2021, primarily conducting cyber espionage against Ukraine and Georgia using custom…

Jul 17, 2026Russia
G0048High

RTM (G0048): A Financially Motivated Cybercriminal Evolution

RTM is a long-standing cybercriminal group, initially focused on banking Trojans, that has evolved into a Ransomware-as-a-Service provider, targeting…

Jul 17, 2026Russia and Neighboring Countries
G1042High

RedEcho: China-Linked Threat Actor Targeting Indian Critical Infrastructure

An in-depth profile of RedEcho (G1042), a China-linked threat actor primarily targeting Indian critical infrastructure, particularly the power sector, for…

Jul 17, 2026China
G0075High

Rancor: Persistent Espionage in Southeast Asia

Rancor (G0075) is a China-linked cyber espionage group targeting government and political entities in Southeast Asia since 2017, employing evolving custom…

Jul 17, 2026China
G0033High

Poseidon Group: The Extortion-as-a-Service Cyber Mercenaries

A profile of the Poseidon Group (G0033), a Brazilian cyber mercenary gang known for its unique data exfiltration and extortion model.

Jul 17, 2026Brazil
G1040Critical

Play Ransomware (G1040) Threat Profile: Evolving Tactics and Global Impact

A detailed security professional's analysis of the Play ransomware group (G1040), its evolving tactics, global targeting, and current active status.

Jul 17, 2026
G0024High

Putter Panda: Persistent Chinese Cyber Espionage

A detailed profile of Putter Panda (G0024), a Chinese state-sponsored threat group linked to the PLA's Unit 61486, focusing on its espionage motivations,…

Jul 17, 2026China
G0056High

PROMETHIUM (StrongPity): A Resilient Espionage Threat

Profile of PROMETHIUM (StrongPity), an espionage-focused APT group active since 2012, known for using trojanized software to target diverse regions and sectors.

Jul 17, 2026Turkey (suspected state-sponsored)