Threat actors

Who is doing this, and how. Intrusion sets come from MITRE ATT&CK with the techniques each group is documented using, so a profile is a list of things to check rather than a description of something frightening. Extortion groups are counted from the victims they have named on their own leak sites.

176
ATT&CK groups tracked
16
Extortion groups
176
Matching this view

HEXANE

G1001

Also known as Lyceum, Siamesekitten, Spirlin

36 documented techniques

EspionageSince 2017

Rocke

G0106

36 documented techniques

Financial gain

TeamPCP

G1056

Also known as PCPCat, ShellForce, DeadCatx3, SHADOW-WATER-058

36 documented techniques

Financial gain

Also known as GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider

34 documented techniques

Financial gainSince 2016

TA505

G0092

Also known as Hive0065, Spandex Tempest, CHIMBORAZO

34 documented techniques

Since 2014

Also known as Evil Corp, Manatee Tempest, DEV-0243, UNC2165

33 documented techniques

Origin: RussiaSince 2014

APT42

G1044

32 documented techniques

Origin: IranEspionage, Data theftSince 2015

APT33

G0064

Also known as HOLMIUM, Elfin, Peach Sandstorm

31 documented techniques

Origin: IranSince 2013

GALLIUM

G0093

Also known as Granite Typhoon

31 documented techniques

EspionageSince 2012

Also known as Storm-1789

30 documented techniques

Origin: North KoreaEspionage, Financial gainSince 2023

Also known as T-APT-04, Rattlesnake

30 documented techniques

Origin: IndiaSince 2012

APT37

G0067

Also known as InkySquid, ScarCruft, Reaper, Group123

29 documented techniques

Origin: North KoreaEspionageSince 2012

APT5

G1023

Also known as Mulberry Typhoon, MANGANESE, BRONZE FLEETWOOD, Keyhole Panda

29 documented techniques

Origin: ChinaEspionageSince 2007

Also known as APT31, Violet Typhoon

29 documented techniques

Origin: ChinaSince 2017

Higaisa

G0126

28 documented techniques

Since 2009

28 documented techniques

Origin: ChinaEspionage

Silence

G0091

Also known as Whisper Spider

28 documented techniques

Financial gain

TA2541

G1018

28 documented techniques

Since 2017

Also known as Teal Kurma, Marbled Dust, Cosmic Wolf, SILICON

27 documented techniques

EspionageSince 2017

Also known as TA473, UAC-0114

27 documented techniques

Origin: RussiaSince 2020

Play

G1040

26 documented techniques

Financial gain, Data theftSince 2022

WIRTE

G0090

Also known as Ashen Lepus

26 documented techniques

Espionage, Sabotage

Intrusion set data is from MITRE ATT&CK, which is maintained by MITRE and released for public use. Extortion group activity is derived from this tracker’s own incident records, sourced from RansomLook under CC BY 4.0.