>samit_hota

Threat Intelligence

Know your adversary

Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.

176 adversary profiles published

G1032High

INC Ransom (G1032) Threat Actor Profile: Operations, Tactics, and Evolution

INC Ransom (G1032), also known as GOLD IONIC, is a prolific RaaS group active since mid-2023, primarily targeting healthcare, education, and manufacturing…

Jul 15, 2026Eastern Europe (Suspected)
G0126High

Higaisa (G0126) Threat Actor Profile

An in-depth profile of Higaisa, a South Korean-suspected APT group targeting government, public, and trade organizations primarily in North Korea and Asia.

Jul 15, 2026South Korea (suspected)
G1001High

HEXANE: Persistent Espionage Targeting Critical Infrastructure

A profile of HEXANE (G1001), an Iranian cyber espionage group targeting oil & gas, telecom, aviation, and ISPs in the Middle East and Africa.

Jul 15, 2026Iran
G0100High

Inception (G0100): A Persistent and Stealthy Cyber Espionage Threat

An in-depth profile of Inception (G0100), a long-running, state-aligned cyber espionage group known for its sophisticated TTPs and global intelligence…

Jul 14, 2026Russia (suspected)
G0125High

HAFNIUM (G0125): A Profile of China's Elite Cyber Espionage Group

An in-depth analysis of HAFNIUM, a state-sponsored Chinese APT group known for sophisticated cyber espionage and rapid exploitation of zero-day vulnerabilities.

Jul 14, 2026China
G0043High

Group5 (G0043): Persistent Iranian-Linked Espionage Targeting Syrian Opposition

Group5 (G0043) is an Iranian-linked threat actor engaged in cyber espionage, primarily targeting individuals associated with the Syrian opposition.

Jul 14, 2026Iran
G0078High

Gorgon Group (G0078): Hybrid Threat Actor Profile

A detailed profile of Gorgon Group (G0078), a Pakistan-linked threat actor known for its dual-pronged approach to cyber espionage and financially motivated…

Jul 14, 2026Pakistan
G0115Critical

GOLD SOUTHFIELD: The Rise and Fall of the REvil Ransomware Empire

A deep dive into GOLD SOUTHFIELD (G0115), the Russian-linked cybercriminal group behind the infamous REvil and GandCrab ransomware-as-a-service operations,…

Jul 14, 2026Russia / Russian-speaking
G0036Medium

GCMAN: A Profile of Financially Motivated Bank Robbers

GCMAN (G0036) is a financially motivated threat group known for targeting financial institutions globally, employing sophisticated APT techniques and…

Jul 14, 2026Suspected Russia
G0047High

Gamaredon Group: Russia's Persistent Espionage Arm in Ukraine and Beyond

Profile of Gamaredon Group (G0047), a Russia-aligned APT linked to the FSB, known for relentless cyber espionage against Ukraine and NATO members.

Jul 14, 2026Russia
G0084High

Gallmaker (G0084): A Profile of Persistent Cyberespionage

A detailed profile of Gallmaker (G0084), a nation-state sponsored cyberespionage group targeting government, military, and defense sectors in the Middle East.

Jul 14, 2026
G0093High

GALLIUM: Persistent Chinese Cyberespionage Targeting Global Critical Infrastructure

GALLIUM (G0093), also known as Granite Typhoon, is a Chinese state-sponsored APT group focused on long-term cyberespionage against global telecommunications,…

Jul 14, 2026China