Threat actors

Who is doing this, and how. Intrusion sets come from MITRE ATT&CK with the techniques each group is documented using, so a profile is a list of things to check rather than a description of something frightening. Extortion groups are counted from the victims they have named on their own leak sites.

176
ATT&CK groups tracked
16
Extortion groups
176
Matching this view

Also known as StrongPity

11 documented techniques

EspionageSince 2012

Also known as Shell Crew, WebMasters, KungFu Kittens, PinkPanther

10 documented techniques

Origin: China

9 documented techniques

Origin: ChinaEspionageSince 2013

Also known as Anunak

9 documented techniques

Since 2013

Also known as Elderwood Gang, Beijing Group, Sneaky Panda

9 documented techniques

Origin: ChinaEspionage

Also known as Pinchy Spider

9 documented techniques

Financial gainSince 2018

Metador

G1013

9 documented techniques

Espionage

Rancor

G0075

9 documented techniques

Sowbug

G0054

9 documented techniques

Since 2015

9 documented techniques

EspionageSince 2017

8 documented techniques

Origin: IranEspionageSince 2013

7 documented techniques

Origin: ChinaEspionageSince 2014

Also known as DustSquad

7 documented techniques

Origin: RussiaEspionageSince 2014

Also known as Plaid Rain

7 documented techniques

Origin: Lebanon

RTM

G0048

7 documented techniques

Since 2015

Windigo

G0124

7 documented techniques

Since 2011

Also known as Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten

6 documented techniques

EspionageSince 2010

6 documented techniques

Espionage

Intrusion set data is from MITRE ATT&CK, which is maintained by MITRE and released for public use. Extortion group activity is derived from this tracker’s own incident records, sourced from RansomLook under CC BY 4.0.