>samit_hota

Threat Intelligence

Know your adversary

Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.

176 adversary profiles published

G0095High

Machete (G0095): Persistent Cyber Espionage in Latin America and Beyond

Machete (G0095) is a long-standing, Spanish-speaking cyber espionage group targeting government, military, and critical infrastructure, primarily in Latin…

Jul 15, 2026Unknown (suspected Spanish-speaking origin, possibly Latin America)
G1014High

LuminousMoth (G1014): Chinese Cyber Espionage Targeting Southeast Asia

LuminousMoth is a Chinese-speaking cyber espionage group (G1014) active since 2020, targeting government entities in Southeast Asia for intelligence gathering.

Jul 15, 2026China
G0030High

Lotus Blossom (G0030): A Persistent Regional Espionage Threat

Lotus Blossom is a China-aligned APT group focused on long-term intelligence collection against government, telecom, and critical infrastructure in Asia.

Jul 15, 2026China
G0065High

Leviathan (APT40): China's Persistent Maritime Espionage Group

A profile of Leviathan (APT40), a Chinese state-sponsored cyber espionage group targeting critical sectors for intelligence and IP theft.

Jul 15, 2026China
G0077High

Threat Profile: Leafminer (G0077) – Iranian Espionage Group

Leafminer (G0077), also known as Raspite, is an Iranian-nexus threat group primarily focused on intelligence collection against critical sectors in the Middle…

Jul 15, 2026Iran
G0140Medium

LazyScripter Threat Profile: Targeting Airlines and Global Workforce

LazyScripter (G0140) is a persistent threat group active since 2018, primarily targeting the airline industry and individuals seeking immigration, using…

Jul 15, 2026Middle East
G0032Critical

Lazarus Group: DPRK's Evolving Hybrid Threat

A detailed profile of the Lazarus Group (G0032), North Korea's state-sponsored cyber threat, covering its origin, motivations, tactics, and recent activities.

Jul 15, 2026North Korea
G1004High

LAPSUS$ (G1004): High-Tempo Social Engineering and Extortion

LAPSUS$ is a cybercriminal group specializing in social engineering and extortion, often without ransomware, targeting global organizations.

Jul 15, 2026Brazil, United Kingdom
G0094Critical

Kimsuky (G0094): North Korea's Relentless Cyber Espionage Arm

A profile of Kimsuky, a North Korean state-sponsored APT group focused on intelligence gathering through sophisticated spear-phishing and evolving malware.

Jul 15, 2026North Korea
G0004High

Ke3chang (G0004): A Persistent Cyberespionage Threat

Ke3chang, also known as APT15 and NICKEL, is a sophisticated Chinese state-sponsored threat group focused on long-term cyberespionage against global…

Jul 15, 2026China
G0119High

Indrik Spider (Evil Corp): A Persistent Russian Cybercriminal Threat

A profile of Indrik Spider, a Russia-based cybercriminal group known for sophisticated banking trojans and evolving ransomware operations.

Jul 15, 2026Russia
G0136High

IndigoZebra (G0136) Threat Profile: Persistent Cyber Espionage in Central Asia

IndigoZebra (G0136) is a suspected Chinese state-sponsored APT group active since 2014, primarily targeting Central Asian governments for cyber espionage.

Jul 15, 2026China