Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
Machete (G0095): Persistent Cyber Espionage in Latin America and Beyond
Machete (G0095) is a long-standing, Spanish-speaking cyber espionage group targeting government, military, and critical infrastructure, primarily in Latin…
LuminousMoth (G1014): Chinese Cyber Espionage Targeting Southeast Asia
LuminousMoth is a Chinese-speaking cyber espionage group (G1014) active since 2020, targeting government entities in Southeast Asia for intelligence gathering.
Lotus Blossom (G0030): A Persistent Regional Espionage Threat
Lotus Blossom is a China-aligned APT group focused on long-term intelligence collection against government, telecom, and critical infrastructure in Asia.
Leviathan (APT40): China's Persistent Maritime Espionage Group
A profile of Leviathan (APT40), a Chinese state-sponsored cyber espionage group targeting critical sectors for intelligence and IP theft.
Threat Profile: Leafminer (G0077) – Iranian Espionage Group
Leafminer (G0077), also known as Raspite, is an Iranian-nexus threat group primarily focused on intelligence collection against critical sectors in the Middle…
LazyScripter Threat Profile: Targeting Airlines and Global Workforce
LazyScripter (G0140) is a persistent threat group active since 2018, primarily targeting the airline industry and individuals seeking immigration, using…
Lazarus Group: DPRK's Evolving Hybrid Threat
A detailed profile of the Lazarus Group (G0032), North Korea's state-sponsored cyber threat, covering its origin, motivations, tactics, and recent activities.
LAPSUS$ (G1004): High-Tempo Social Engineering and Extortion
LAPSUS$ is a cybercriminal group specializing in social engineering and extortion, often without ransomware, targeting global organizations.
Kimsuky (G0094): North Korea's Relentless Cyber Espionage Arm
A profile of Kimsuky, a North Korean state-sponsored APT group focused on intelligence gathering through sophisticated spear-phishing and evolving malware.
Ke3chang (G0004): A Persistent Cyberespionage Threat
Ke3chang, also known as APT15 and NICKEL, is a sophisticated Chinese state-sponsored threat group focused on long-term cyberespionage against global…
Indrik Spider (Evil Corp): A Persistent Russian Cybercriminal Threat
A profile of Indrik Spider, a Russia-based cybercriminal group known for sophisticated banking trojans and evolving ransomware operations.
IndigoZebra (G0136) Threat Profile: Persistent Cyber Espionage in Central Asia
IndigoZebra (G0136) is a suspected Chinese state-sponsored APT group active since 2014, primarily targeting Central Asian governments for cyber espionage.
No adversaries match your search.