Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
POLONIUM (G1005): Persistent Cyber Espionage Targeting Israel
POLONIUM is a Lebanon-based, Iran-affiliated cyber espionage group actively targeting critical sectors in Israel with custom backdoors and cloud-based C2.
PLATINUM (G0068) Threat Actor Profile: Stealthy Cyber Espionage in APAC
A deep dive into PLATINUM (G0068), an advanced, state-sponsored cyber espionage group targeting governments and critical infrastructure in South and Southeast…
MuddyWater (G0069) - Iran's Persistent Cyber Espionage Group
A deep dive into MuddyWater (G0069), an Iranian state-sponsored APT group known for persistent cyber espionage and evolving tactics.
PittyTiger: Persistent Espionage from the Far East
A detailed profile of PittyTiger (G0011), a suspected Chinese state-sponsored threat actor focused on cyber espionage.
Patchwork (G0040): A Persistent Indian Cyber Espionage Threat
An in-depth profile of Patchwork (G0040), a pro-Indian cyber espionage group actively targeting government, diplomatic, and defense sectors globally.
Orangeworm: Healthcare's Silent Threat
Orangeworm (G0071) is a sophisticated threat actor primarily targeting the global healthcare sector for corporate espionage.
OilRig (G0049) - Iran's Persistent Cyber Espionage Arm
OilRig, an Iranian state-sponsored APT group (G0049), actively targets Middle Eastern and international entities for cyber espionage, leveraging advanced TTPs.
Nomadic Octopus: Persistent Cyber Espionage in Central Asia
A profile of Nomadic Octopus (G0133), a Russia-linked cyber espionage group targeting Central Asian governments, diplomatic entities, and critical…
NEODYMIUM (G0055): A Cyber Espionage Threat Targeting Turkey
A profile of NEODYMIUM (G0055), a cyber espionage threat actor with suspected Iranian links, known for targeting Turkish individuals and organizations.
Naikon (G0019) Threat Profile: Persistent Chinese Cyber Espionage
Naikon is a state-sponsored Chinese cyber espionage group (G0019) primarily targeting government, military, and civil organizations in Southeast Asia for…
Threat Profile: Mustard Tempest (G1020)
An in-depth profile of Mustard Tempest (G1020), a financially motivated initial access broker known for distributing SocGholish malware.
Mustang Panda (G0129): China-Aligned Cyber Espionage Group Profile
A detailed threat actor profile of Mustang Panda (G0129), a China-aligned cyber espionage group known for its persistent and adaptive operations.
No adversaries match your search.