Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
MoustachedBouncer (G1019) Threat Profile: Belarusian Cyberespionage Group
An in-depth profile of MoustachedBouncer, a Belarusian-aligned cyberespionage group targeting foreign embassies through sophisticated ISP-level attacks and…
Moses Staff (G1009) Threat Actor Profile
Moses Staff (G1009), also known as DEV-0500 and Marigold Sandstorm, is an Iranian-backed threat group primarily focused on politically motivated destructive…
Moonstone Sleet (G1036) Threat Actor Profile
Moonstone Sleet is a North Korean-linked threat actor conducting financially motivated and espionage operations, notable for social engineering and custom…
Molerats (G0021): Persistent Cyber Espionage in the Middle East
A profile of Molerats (G0021), a politically-motivated, Hamas-aligned APT group active since 2012, known for cyber espionage in the Middle East and beyond.
Mofang (G0103): Persistent Cyber Espionage Operations
A detailed profile of Mofang (G0103), a likely China-based, government-affiliated cyber espionage group known for its sophisticated TTPs.
Moafee (G0002): Profile of a Chinese Espionage Threat Actor
Moafee (G0002) is a China-linked threat group primarily focused on information theft and espionage against government and military targets.
MirrorFace (G1054) - PRC-Aligned Cyberespionage Group with Evolving TTPs
MirrorFace, also known as Earth Kasha, is a sophisticated PRC-aligned cyberespionage group actively targeting government, critical infrastructure, and…
Metador (G1013): An Elusive Cyber Espionage Group
Metador (G1013) is a sophisticated and highly-aware cyber espionage group targeting telecommunication companies, ISPs, and universities in the Middle East and…
menuPass (G0045): China's Enduring Cyber Espionage Arm
menuPass, also known as APT10, is a highly sophisticated Chinese state-sponsored cyber espionage group primarily focused on intellectual property theft and…
Medusa Group: An Aggressive RaaS with Evolving Extortion Tactics
Medusa Group is an aggressive Ransomware-as-a-Service (RaaS) operation known for double and triple extortion, targeting critical sectors globally with a focus…
Malteiro (G1026) Threat Profile: Mispadu MaaS and Latin American Banking Threats
A profile of Malteiro (G1026), a Brazilian cybercrime group known for distributing the Mispadu banking trojan via a Malware-as-a-Service model.
Magic Hound (G0059) Threat Profile: Iran's Persistent Cyber Espionage
A detailed threat profile for Magic Hound (G0059), an Iranian-sponsored cyber espionage group, outlining their operations, targets, TTPs, and current status.
No adversaries match your search.