Threat actors

Who is doing this, and how. Intrusion sets come from MITRE ATT&CK with the techniques each group is documented using, so a profile is a list of things to check rather than a description of something frightening. Extortion groups are counted from the victims they have named on their own leak sites.

176
ATT&CK groups tracked
16
Extortion groups
176
Matching this view

Mofang

G0103

6 documented techniques

Origin: ChinaEspionage

TA577

G1037

6 documented techniques

Also known as Blackfly

6 documented techniques

Since 2010

APT12

G0005

Also known as IXESHE, DynCalc, Numbered Panda, DNSCALC

5 documented techniques

Origin: China

Cleaver

G0003

Also known as Threat Group 2889, TG-2889

5 documented techniques

Origin: Iran

RedEcho

G1042

5 documented techniques

Origin: China

Suckfly

G0039

5 documented techniques

Origin: ChinaSince 2014

TA459

G0062

5 documented techniques

Also known as Lebanese Cedar

5 documented techniques

Origin: LebanonSince 2012

Group5

G0043

4 documented techniques

Origin: Iran

Also known as APT2, MSUpdater

4 documented techniques

Origin: China

4 documented techniques

Origin: NigeriaSince 2014

TA578

G1038

4 documented techniques

Thrip

G0076

4 documented techniques

Espionage

Strider

G0041

Also known as ProjectSauron

3 documented techniques

Since 2011

Also known as GOLD FEATHER

3 documented techniques

Origin: RussiaFinancial gainSince 2022

Also known as Gleaming Pisces, Citrine Sleet, UNC1720, UNC4736

2 documented techniques

Origin: North KoreaSince 2018

APT17

G0025

Also known as Deputy Dog

2 documented techniques

Origin: China

APT30

G0013

2 documented techniques

Origin: China

GCMAN

G0036

2 documented techniques

2 documented techniques

EspionageSince 2015

Intrusion set data is from MITRE ATT&CK, which is maintained by MITRE and released for public use. Extortion group activity is derived from this tracker’s own incident records, sourced from RansomLook under CC BY 4.0.