189 threats
Chinese threat group targeting defense and high-tech organizations using spear-phishing and custom backdoors since at least 2008.
Iranian threat actor conducting destructive wiper attacks and ransomware operations primarily against Israeli targets, masking espionage with sabotage.
Iranian threat group active since 2010, targeting defense industrial base and Iranian dissidents using social engineering and custom malware.
Russian threat group targeting electric utility organizations in the US and UK, focused on ICS reconnaissance and maintaining persistent access.
Chinese-speaking APT active since 2013 targeting government, education, and telecom organizations across Southeast Asia and Australia.
North Korean sub-group of Lazarus focused on cryptocurrency theft through trojanized trading applications and supply chain attacks.
Chinese state-linked group conducting dual espionage and financial cybercrime operations, notorious for supply chain compromises and the ShadowPad backdoor.
South Asian APT targeting government and military organizations in Pakistan, Bangladesh, and China with custom downloaders and RATs via spearphishing.
Middle Eastern threat group conducting surveillance and espionage against military and government targets across the region since 2012.
Spanish-speaking threat group targeting Colombian and Ecuadorian government, financial, and energy organizations with commodity RATs.
PLA Unit 61398 threat group that systematically stole hundreds of terabytes of data from at least 141 organizations across 20 industries since 2006.
Chinese threat group targeting media organizations, high-tech companies, and government entities since at least 2009.
China-based group targeting Japanese and Taiwanese organizations, particularly media and government entities.
Chinese threat group exploiting zero-day vulnerabilities and using legitimate websites for C2 to target US government and defense organizations.
Chinese group responsible for the massive 2015 healthcare breach stealing 78.8 million patient records, also targeting aerospace and defense.
Chinese group targeting law firms and investment companies, known for using strategic web compromises and zero-day exploits.
Chinese state-sponsored APT conducting espionage against defense, aerospace, and government sectors worldwide using custom backdoors and supply chain attacks.
Russian SVR intelligence group responsible for the SolarWinds supply chain attack affecting 18,000+ organizations. One of the most sophisticated APTs globally.
Chinese MSS-affiliated group (Boyusec) conducting espionage through zero-day exploits and strategic web compromises, indicted by US DOJ in 2017.
Chinese APT conducting long-running espionage operations since 2005 targeting ASEAN member states and India with air-gapped network infiltration capabilities.
Vietnamese state-sponsored group targeting private sector, foreign governments, and journalists with sophisticated custom malware and social engineering.
Iranian group targeting aerospace and energy sectors globally, linked to destructive attacks using Shamoon wiper and password spraying campaigns.
North Korean group primarily targeting South Korean organizations using zero-day exploits, strategic web compromises, and mobile malware.
North Korean group focused on financial theft, responsible for the $81M Bangladesh Bank heist and attacks on banks across 11+ countries via SWIFT.
Iranian MOIS-affiliated group focused on surveillance of individuals through telecom and travel industry compromise since 2014.
Iranian IRGC-IO group conducting credential harvesting and surveillance against journalists, activists, and Western government officials.
Chinese APT targeting telecommunications and technology organizations, known for exploiting Pulse Secure VPN and Citrix vulnerabilities.
Chinese threat group conducting intelligence collection and industrial espionage using Log4Shell and other vulnerabilities since 2020.
Chinese state-sponsored group conducting large-scale cyber espionage against government and critical infrastructure worldwide since 2008.
Chinese APT targeting ministries of foreign affairs and telecoms in Africa, Middle East, and Central Asia with custom backdoors.
Long-running Chinese APT using the custom Bisonal RAT to target military and government organizations across East Asia and Eastern Europe.
Middle Eastern threat actor using zero-day exploits (particularly Flash) for surveillance against UN officials, journalists, and activists.
Chinese state-sponsored group targeting Japan and Taiwan, known for modifying router firmware to maintain persistent access to networks.
Financially motivated group exploiting web application vulnerabilities to deploy Monero cryptocurrency miners on Windows systems.
Threat group deploying Android surveillance malware targeting military personnel in Middle Eastern countries.
Chinese espionage group conducting intellectual property theft from Japanese defense and technology organizations since 2006.
Financially motivated group that stole over $1 billion from banks worldwide by compromising internal banking systems and manipulating ATMs.
Iranian IRGC-affiliated APT conducting sophisticated social engineering and credential harvesting campaigns against academics, journalists, and government officials worldwide.
Chinese threat group targeting semiconductor and airline industries for intellectual property theft, using Cobalt Strike and custom DLL loaders.
MTAC threat intelligence report analyzing 22,705 hostile activities from 3,321 Chinese source IPs targeting 4 countries, with attribution to APT10, APT27, Mustang Panda, APT41, and Volt Typhoon.
Chinese group deploying ransomware (HUI Loader, Cobalt Strike) potentially as cover for espionage, cycling through multiple ransomware families.
Iranian group conducting Operation Cleaver targeting critical infrastructure across 16 countries including military, energy, and aviation.
Financially motivated group targeting banks worldwide through ATM jackpotting and SWIFT transaction manipulation using Cobalt Strike.
Indian-origin APT conducting espionage against Pakistani military and government targets using mobile and desktop malware.
North Korean campaign targeting software developers through fake job interviews to deliver malware that steals cryptocurrency and credentials.
Iranian group targeting Israeli and German government and academic organizations using custom malware and strategic web compromises.
How APT groups like Imperial Kitten, APT33, and MuddyWater execute sustained cyberattacks, and Mjolnir Security's approach to countering them.
Iranian group building elaborate fake social media personas to establish trust with targets before delivering malware over months-long engagements.
IRGC-affiliated group targeting water treatment facilities and industrial control systems, notably hacking Unitronics PLCs in the US.
Chinese APT active since 2012 targeting telecoms and government in Africa and Asia, known for MgBot malware and macOS capabilities.
Lebanese intelligence-linked group conducting global mobile surveillance campaign stealing data from Android devices across 21+ countries.
APT targeting business executives and government officials through hotel Wi-Fi networks, using zero-days and stolen certificates since 2007.
Threat group targeting Middle Eastern government and education with custom tools leveraging open-source offensive frameworks.
Financially motivated group physically planting rogue devices (Raspberry Pi, Bash Bunny) inside bank offices for network penetration.
Chinese group responsible for the 2015 Anthem healthcare breach (80M records) and targeting US government personnel databases.
Russian FSB group targeting Western energy and nuclear facilities since 2011, gaining operational access to ICS/SCADA systems.
Chinese group targeting Japanese and Taiwanese high-tech and manufacturing organizations with commodity and custom malware.
Advanced APT targeting Southeast Asian governments with rootkit-level persistence, kernel-mode implants, and cloud-based exfiltration via Dropbox and OneDrive.
Chinese group blending espionage with financially motivated attacks, targeting government and tech sectors through web-facing server exploitation.
Chinese group behind 2009 Operation Aurora targeting Google and 20+ companies, pioneering zero-day supply chain attacks.
Russian GRU group conducting destructive operations against Ukraine using WhisperGate wiper and defacing government websites before the 2022 invasion.
Highly sophisticated group (attributed to NSA TAO) active since 2001, using HDD firmware implants and air-gap jumping capabilities.
Financially motivated group targeting fintech and cryptocurrency companies with JavaScript-based malware and social engineering.
Initial access broker using elaborate business proposal phishing with custom file-sharing services to deliver BazarLoader and ransomware.
Iranian group targeting domestic dissidents and Persian-speaking individuals with MarkiRAT surveillance malware since 2015.
Financially motivated group extorting Canadian organizations with threats to leak stolen data, active 2013-2016.
Financially motivated group conducting slow, stealthy intrusions in Latin American banks to manipulate financial transactions over months.
Group targeting healthcare and M&A advisory firms to steal insider trading information from corporate email accounts.
Financially motivated group stealing payment card data from hospitality and restaurant point-of-sale systems since 2008.
Financially motivated threat group specializing in payment card theft from POS systems and e-commerce platforms, responsible for millions of stolen card numbers across retail and hospitality.
Prolific eCrime group responsible for over $1 billion in theft, evolving from POS malware to ransomware affiliate operations while operating a fake pentesting company (Combi Security, Bastion Secure).
Financially motivated group conducting POS malware campaigns against retail and hospitality organizations since 2016.
Iranian group acting as initial access broker, exploiting VPN vulnerabilities (Pulse Secure, Fortinet, F5) and selling access to ransomware operators.
Chinese group targeting global telecommunications providers to conduct surveillance, exploiting public-facing web servers for initial access.
Espionage group using living-off-the-land techniques exclusively, avoiding custom malware to target government and military organizations.
Russian FSB-linked APT from occupied Crimea conducting high-volume, persistent espionage operations against Ukrainian government and military organizations.
Financially motivated group using legitimate penetration testing tools to transfer money from banks, capping at amounts below alert thresholds.
Highly sophisticated Chinese APT deploying kernel-level rootkits and advanced anti-forensic techniques to maintain persistent access in telecom and government networks.
Ransomware group operating the REvil/Sodinokibi Ransomware-as-a-Service, responsible for Kaseya supply chain attack affecting 1,500+ businesses.
Financially motivated APT targeting fintech and cryptocurrency companies using the Golden Chickens MaaS suite and custom JavaScript malware.
Pakistani threat group conducting both espionage and criminal operations using commodity RATs distributed through spear-phishing.
Threat group targeting the Syrian opposition using commercial RATs and social engineering over social media platforms.
Chinese state-sponsored group exploiting Microsoft Exchange ProxyLogon zero-days (CVE-2021-26855) to compromise 30,000+ organizations globally.
Iranian group targeting Middle Eastern and African telecoms and oil companies using DNS tunneling and custom .NET backdoors.
Group targeting North Korean government interests and Chinese organizations using LNK file-based attacks and DLL side-loading.
Ransomware group active since 2023 targeting healthcare and education with double extortion, known for publishing stolen data on leak sites.
Sophisticated group using cloud services for C2 and targeting government organizations in Russia and Central Asia since 2012.
Chinese group targeting Central Asian government entities using Dropbox and other cloud services as C2 infrastructure.
Russian cybercrime group behind Dridex, BitPaymer, WastedLocker, and Hades ransomware. Leader Maksim Yakubets has $5M FBI bounty.
Intelligence update on Iranian cyber threats post-Operation Epic Fury. Expect destructive wipers, ICS/SCADA attacks, and AI-enabled influence operations.
Chinese group targeting diplomatic missions and government organizations worldwide since 2010, known for Ketrican and Okrum backdoors.
North Korean intelligence-gathering APT specializing in social engineering against South Korean policy experts, defectors, and academics with credential harvesting and custom backdoors.
North Korea's most prolific APT group, responsible for the Sony hack, WannaCry, Bangladesh Bank heist, and billions in cryptocurrency theft to fund the DPRK weapons program.
Threat group targeting airline industry and IATA members using KOCTOPUS loader and Empire framework since 2018.
Iranian group targeting Middle Eastern government and business organizations using publicly available tools and vulnerability scanning.
Chinese MSS-directed (Hainan province) group targeting maritime, defense, and aviation. Indicted by US DOJ in 2021 for global espionage campaign.
Chinese APT targeting Southeast Asian government and military organizations with custom backdoors, leveraging diplomatic-themed lures and strategic watering hole attacks.
Chinese-linked APT conducting targeted espionage campaigns against Tibetan activists, Japanese aerospace entities, and Indian military organizations.
Chinese-speaking group targeting Southeast Asian government entities with USB spreading malware and Zoom installer hijacking.
Spanish-speaking group conducting espionage against Latin American military and government institutions since 2010.
Brazilian threat group distributing banking trojans targeting Latin American financial institutions through malspam campaigns.
Ransomware group operating Medusa RaaS since 2022, using double extortion and a public Tor-based leak site for victim data.
China MSS-affiliated APT targeting managed service providers to pivot into client networks, conducting massive intellectual property theft across defense, healthcare, and aerospace sectors.
Highly sophisticated group targeting telecoms and ISPs using multi-layered malware platforms with years-long persistence.
Chinese group associated with military interests targeting US defense organizations with custom malware.
Chinese espionage group targeting government and critical infrastructure in Myanmar and other countries using ShimRat malware.
Palestinian group conducting espionage against Israeli and Middle Eastern targets using social engineering and commodity RATs since 2012.
North Korean group using fake companies, trojanized software, and custom ransomware (FakePenny) to fund DPRK operations.
Iranian group conducting destructive attacks against Israeli organizations, encrypting systems without providing decryption capability.
Belarusian group targeting foreign embassies in Belarus using ISP-level adversary-in-the-middle attacks for malware delivery.
Iranian MOIS-subordinate APT conducting espionage across the Middle East using custom C2 frameworks, heavy PowerShell usage, and living-off-the-land techniques.
Chinese APT targeting European and Asian government organizations and NGOs with PlugX variants and custom backdoors via USB propagation and spearphishing.
Initial access broker distributing SocGholish fake browser updates to deliver ransomware and other payloads to compromised websites.
Chinese PLA-linked group conducting espionage against Southeast Asian government and military targets since 2005.
Group using zero-day exploits and FinFisher surveillance software to target individuals in Turkey.
Group targeting Central Asian diplomatic and government entities using custom Android and Windows malware.
Iranian MOIS group conducting espionage across the Middle East since 2014 using DNS tunneling, custom tools, and social engineering.
North Korean APT conducting dual espionage and ransomware operations against defense, energy, and healthcare sectors using custom implants and opportunistic vulnerability exploitation.
Group targeting healthcare organizations and their supply chain to access patient data and medical device information.
Indian-linked APT targeting Pakistan and China with copy-paste code from multiple sources, known for occasionally infecting their own systems with their own malware.
Chinese group targeting defense and telecom sectors using Gh0st RAT and Troj/Reader-AJ since 2011.
Sophisticated group using hotpatching for fileless execution and targeting South Asian government and ISP organizations.
Ransomware group active since 2022 using double extortion, known for exploiting FortiOS and Microsoft Exchange vulnerabilities.
Lebanon-based, Iran-backed APT exclusively targeting Israeli organizations using OneDrive for C2 and a suite of custom 'Creepy' implants.
Brazilian group conducting targeted attacks to steal proprietary information and blackmail victims into hiring them as security consultants.
Turkish-linked group targeting Kurdish and opposition groups by trojanizing legitimate software installers with surveillance capabilities.
Chinese PLA Unit 61486 group targeting US defense and space sectors to steal satellite and aerospace technology.
Chinese group targeting Southeast Asian government entities using PLAINTEE and DDKONG malware families.
Group conducting stealthy corporate espionage targeting HR and legal departments to steal internal documents and business intelligence.
Chinese group targeting Indian power grid infrastructure with ShadowPad malware, potentially pre-positioning for disruptive operations.
Chinese group deploying cryptocurrency miners at scale on compromised Linux and cloud servers, evading detection by killing competing miners.
Russian cybercrime group targeting Russian banking organizations to steal funds through manipulated accounting software transactions.
Russian group targeting Ukrainian and Georgian government organizations with destructive payloads during the Russia-Ukraine conflict.
Russian GRU Unit 74455 responsible for NotPetya ($10B damage), BlackEnergy grid attacks, Olympic Destroyer, and ongoing Ukraine cyber operations.
Chinese group targeting Uyghur and Tibetan minority activists using mobile and desktop surveillance malware.
Group conducting DNS hijacking campaigns targeting government and telecom organizations across the Middle East and North Africa.
Chinese APT targeting ASEAN government ministries using the RoyalRoad RTF weaponizer and custom Soul framework for long-term espionage operations.
Pakistani group mimicking Sidewinder TTPs to target Indian military and defense organizations with custom RATs.
Indian APT targeting Pakistan and China military and government since 2012, one of the most active APTs by volume of operations.
Russian-speaking group targeting financial organizations and ATM systems primarily in CIS countries, stealing millions via ATM jackpotting.
Iranian group conducting credential harvesting campaigns against 300+ universities in 30+ countries to steal academic research and IP.
Central Asian APT targeting government entities and embassies in the region with PowerShell-based implants and Telegram bot infrastructure for C2.
Nigerian cybercrime group conducting business email compromise (BEC) campaigns responsible for billions in global losses.
Russia GRU military intelligence APT responsible for DNC hack, WADA breach, NotPetya, and persistent targeting of NATO governments and elections infrastructure worldwide.
Espionage group targeting South American and Southeast Asian foreign affairs ministries using Felismus backdoor.
Russian FSB group conducting credential phishing against academics, defense officials, and NGOs to collect intelligence since 2017.
UAE-linked group conducting surveillance against dissidents, journalists, and activists using sophisticated spyware.
Financially motivated group pivoting from on-premises to cloud, deploying Embargo ransomware against US organizations.
Financially motivated group abusing Microsoft Quick Assist remote support tool for social engineering to deploy Black Basta ransomware.
Highly sophisticated group using air-gap-defeating modular malware platform active since 2011, discovered by Kaspersky in 2016.
Chinese group using stolen code signing certificates to attack Indian government and commercial organizations.
Persistent threat group targeting aviation and defense industries since 2017 using commodity RATs via large-scale phishing campaigns.
Threat actor distributing platform-specific payloads via web injects and fake browser updates, delivering FrigidStealer on macOS, Marcher on Android, and Lumma on Windows.
Chinese APT closely related to Mustang Panda, targeting European diplomatic missions and the Vatican with PlugX and custom malware via carefully crafted spearphishing campaigns.
Chinese group targeting Central Asian military and government using exploits for Microsoft Office vulnerabilities.
Major cybercrime group distributing Dridex, Locky, Clop ransomware, and FlawedAmmyy at massive scale via Necurs botnet.
Malware distribution group using thread-hijacked email campaigns to deliver IcedID, QakBot, and Ursnif banking trojans.
Prolific initial access broker distributing QakBot and Pikabot via thread-hijacked email campaigns at high volume.
Initial access broker using contact form and callback phishing to deliver BazarLoader, Bumblebee, and Latrodectus.
Cloud-focused group targeting misconfigured Docker and Kubernetes environments to deploy cryptocurrency miners and steal credentials.
Russian group behind TRITON/TRISIS malware targeting Schneider Electric Triconex safety systems, capable of causing physical destruction.
Deconstructing Salt Typhoon, one of China's most sophisticated state-sponsored APT groups targeting telecommunications and critical infrastructure worldwide.
An anthropological and geopolitical analysis of Iranian state-sponsored APT groups weaponizing cyberspace against North American critical infrastructure.
Sophisticated group targeting Pakistani military and nuclear program with malware designed to evade 8+ antivirus products.
Threat group targeting financial organizations using SWIFT manipulation techniques to conduct fraudulent transactions.
Chinese group targeting satellite operators, telecoms, and defense organizations in Southeast Asia and the US.
Sophisticated Chinese APT targeting government and military in Asia and Europe since 2020, using custom loaders and passive backdoors.
Chinese group targeting military and government organizations in Russia, South Korea, and Japan using Bisonal and ShadowPad.
Pakistan-linked APT persistently targeting Indian military and government with CrimsonRAT, fake romance apps, and Android malware for espionage operations.
Chinese group targeting Taiwanese and Philippine government and military organizations with custom USB-spreading malware since 2011.
Russian FSB group active since 1996, one of the most sophisticated APTs using satellite-based C2 and hijacking other APT infrastructure.
Threat cluster operating Cuba ransomware with custom loaders and kernel driver exploits, targeting critical infrastructure and government organizations for double extortion.
Chinese group exploiting zero-days in VMware and Fortinet appliances to maintain persistent access to hypervisors and network edge devices.
Chinese-nexus APT exploiting CVE-2023-2868 in Barracuda Email Security Gateway appliances to deploy custom backdoors across government and critical infrastructure globally.
Chinese threat actor blending espionage with cybercrime, exploiting Ivanti, F5, and Atlassian vulnerabilities using open-source C2 frameworks to target defense and research institutions.
Iranian group conducting espionage operations against Middle Eastern government and telecommunications organizations.
Analysis of unattributed advanced persistent threat clusters that don't match known APT groups, featuring novel TTPs and infrastructure that defy conventional classification.
Chinese group maintaining years-long persistence in F5 BIG-IP and other network appliances, demonstrating exceptional operational stealth.
Operator of the Golden Chickens MaaS suite providing more_eggs backdoor to FIN6, Cobalt Group, and Evilnum, targeting corporate HR departments via fake job applications.
Lebanese group targeting military and telecom organizations across the Middle East and beyond using Explosive RAT since 2012.
Chinese state-sponsored group pre-positioning in US critical infrastructure (energy, water, telecom, ports) for potential disruption during geopolitical crisis.
Group targeting Philippine government organizations using spear-phishing and custom malware since 2022.
Group responsible for the 2018 SingHealth breach stealing 1.5 million patient records including the Singapore Prime Minister's data.
Operation Windigo compromised 25,000+ Linux servers for spam distribution, click fraud, and malware delivery since 2011.
Group conducting surveillance against specific individuals in the Middle East using macOS and mobile malware.
Russia-aligned group exploiting Zimbra and Roundcube zero-days to target European government and NATO-aligned diplomatic entities.
Middle Eastern group linked to Gaza Cybergang conducting espionage against government and diplomatic entities in the region.
Russian cybercrime group behind TrickBot, Conti, Ryuk, and BazarLoader - one of the most prolific ransomware operations generating $200M+ in revenue.
Chinese MSS-affiliated group (Wuhan Xiaoruizhi) targeting government and technology organizations worldwide, indicted by US DOJ in 2024.