Threat actors

Who is doing this, and how. Intrusion sets come from MITRE ATT&CK with the techniques each group is documented using, so a profile is a list of things to check rather than a description of something frightening. Extortion groups are counted from the victims they have named on their own leak sites.

176
ATT&CK groups tracked
16
Extortion groups
176
Matching this view

16 documented techniques

Origin: PakistanSince 2019

Also known as Earth Akhlut, BRONZE HUNTLEY, CactusPete, Karma Panda

15 documented techniques

Origin: ChinaEspionageSince 2009

Also known as Palmerworm

14 documented techniques

Origin: ChinaEspionageSince 2013

Naikon

G0019

14 documented techniques

Origin: ChinaEspionageSince 2010

TA551

G0127

Also known as GOLD CABIN, Shathak

14 documented techniques

Since 2018

Also known as COPPER FIELDSTONE, APT36, Mythic Leopard, ProjectM

14 documented techniques

Origin: PakistanSince 2013

Also known as TA407, COBALT DICKENS

13 documented techniques

Since 2013

12 documented techniques

Origin: China

Also known as Silent Chollima, PLUTONIUM, Onyx Sleet

12 documented techniques

Origin: North KoreaSabotageSince 2009

APT18

G0026

Also known as TG-0416, Dynamite Panda, Threat Group-0416

12 documented techniques

Since 2009

12 documented techniques

Origin: LebanonSince 2012

FIN4

G0085

12 documented techniques

Since 2013

12 documented techniques

Financial gain

Also known as DEV-0500, Marigold Sandstorm

12 documented techniques

Origin: Iran

Also known as DEV-0206, TA569, GOLD PRELUDE, UNC1543

12 documented techniques

Since 2017

Evilnum

G0120

11 documented techniques

Financial gainSince 2018

FIN10

G0051

11 documented techniques

Financial gain, Data theftSince 2013

FIN5

G0053

11 documented techniques

Financial gainSince 2008

Machete

G0095

Also known as APT-C-43, El Machete

11 documented techniques

EspionageSince 2010

11 documented techniques

Since 2009

Intrusion set data is from MITRE ATT&CK, which is maintained by MITRE and released for public use. Extortion group activity is derived from this tracker’s own incident records, sourced from RansomLook under CC BY 4.0.