Threat Intelligence
Know your adversary
Profiles of documented threat actor groups — who they are, how they operate, and what they've been observed doing.
176 adversary profiles published
INC Ransom (G1032) Threat Actor Profile: Operations, Tactics, and Evolution
INC Ransom (G1032), also known as GOLD IONIC, is a prolific RaaS group active since mid-2023, primarily targeting healthcare, education, and manufacturing…
Higaisa (G0126) Threat Actor Profile
An in-depth profile of Higaisa, a South Korean-suspected APT group targeting government, public, and trade organizations primarily in North Korea and Asia.
HEXANE: Persistent Espionage Targeting Critical Infrastructure
A profile of HEXANE (G1001), an Iranian cyber espionage group targeting oil & gas, telecom, aviation, and ISPs in the Middle East and Africa.
Inception (G0100): A Persistent and Stealthy Cyber Espionage Threat
An in-depth profile of Inception (G0100), a long-running, state-aligned cyber espionage group known for its sophisticated TTPs and global intelligence…
HAFNIUM (G0125): A Profile of China's Elite Cyber Espionage Group
An in-depth analysis of HAFNIUM, a state-sponsored Chinese APT group known for sophisticated cyber espionage and rapid exploitation of zero-day vulnerabilities.
Group5 (G0043): Persistent Iranian-Linked Espionage Targeting Syrian Opposition
Group5 (G0043) is an Iranian-linked threat actor engaged in cyber espionage, primarily targeting individuals associated with the Syrian opposition.
Gorgon Group (G0078): Hybrid Threat Actor Profile
A detailed profile of Gorgon Group (G0078), a Pakistan-linked threat actor known for its dual-pronged approach to cyber espionage and financially motivated…
GOLD SOUTHFIELD: The Rise and Fall of the REvil Ransomware Empire
A deep dive into GOLD SOUTHFIELD (G0115), the Russian-linked cybercriminal group behind the infamous REvil and GandCrab ransomware-as-a-service operations,…
GCMAN: A Profile of Financially Motivated Bank Robbers
GCMAN (G0036) is a financially motivated threat group known for targeting financial institutions globally, employing sophisticated APT techniques and…
Gamaredon Group: Russia's Persistent Espionage Arm in Ukraine and Beyond
Profile of Gamaredon Group (G0047), a Russia-aligned APT linked to the FSB, known for relentless cyber espionage against Ukraine and NATO members.
Gallmaker (G0084): A Profile of Persistent Cyberespionage
A detailed profile of Gallmaker (G0084), a nation-state sponsored cyberespionage group targeting government, military, and defense sectors in the Middle East.
GALLIUM: Persistent Chinese Cyberespionage Targeting Global Critical Infrastructure
GALLIUM (G0093), also known as Granite Typhoon, is a Chinese state-sponsored APT group focused on long-term cyberespionage against global telecommunications,…
No adversaries match your search.