Threat actors

Who is doing this, and how. Intrusion sets come from MITRE ATT&CK with the techniques each group is documented using, so a profile is a list of things to check rather than a description of something frightening. Extortion groups are counted from the victims they have named on their own leak sites.

176
ATT&CK groups tracked
16
Extortion groups
176
Matching this view

Also known as GOLD IONIC

25 documented techniques

Financial gain

25 documented techniques

Since 2020

Also known as DUBNIUM, Zigzag Hail

24 documented techniques

Origin: South KoreaEspionageSince 2004

APT1

G0006

Also known as Comment Crew, Comment Group, Comment Panda

23 documented techniques

Origin: China

Agrius

G1030

Also known as Pink Sandstorm, AMERICIUM, Agonizing Serpens, BlackShadow

22 documented techniques

Origin: IranSabotageSince 2020

Also known as Inception Framework, Cloud Atlas

22 documented techniques

EspionageSince 2014

APT19

G0073

Also known as Codoso, C0d0so0, Codoso Team, Sunshop Group

21 documented techniques

Origin: China

Also known as DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon

21 documented techniques

Since 2009

Also known as SEABORGIUM, Callisto Group, TA446, COLDRIVER

20 documented techniques

Origin: RussiaEspionageSince 2019

Also known as DEV-0401, Emperor Dragonfly, BRONZE STARLIGHT

19 documented techniques

Origin: ChinaEspionage, Financial gainSince 2021

Also known as Confucius APT

19 documented techniques

EspionageSince 2013

CURIUM

G1012

Also known as Crimson Sandstorm, TA456, Tortoise Shell, Yellow Liderc

19 documented techniques

Origin: Iran

Also known as Bahamut

19 documented techniques

Since 2017

Also known as Storm-0587, TA471, UAC-0056, Lorec53

18 documented techniques

Origin: Russia

Akira

G1024

Also known as GOLD SAHARA, PUNK SPIDER, Howling Scorpius

17 documented techniques

Financial gain, Data theft

Also known as Evasive Panda, BRONZE HIGHLAND

17 documented techniques

Origin: ChinaSince 2012

Also known as Raspite

17 documented techniques

Origin: Iran

Axiom

G0001

Also known as Group 72

16 documented techniques

Origin: ChinaEspionageSince 2008

BITTER

G1002

Also known as T-APT-17

16 documented techniques

EspionageSince 2013

Also known as Operation Molerats, Gaza Cybergang

16 documented techniques

Since 2012

Intrusion set data is from MITRE ATT&CK, which is maintained by MITRE and released for public use. Extortion group activity is derived from this tracker’s own incident records, sourced from RansomLook under CC BY 4.0.