Threat actors

Who is doing this, and how. Intrusion sets come from MITRE ATT&CK with the techniques each group is documented using, so a profile is a list of things to check rather than a description of something frightening. Extortion groups are counted from the victims they have named on their own leak sites.

176
ATT&CK groups tracked
16
Extortion groups
176
Matching this view

APT16

G0023

1 documented techniques

Origin: China

Moafee

G0002

1 documented techniques

Also known as Mantis, Arid Viper, Desert Falcon, TAG-63

0 documented techniques

Since 2014

Also known as XENOTIME

0 documented techniques

Origin: Russia

Intrusion set data is from MITRE ATT&CK, which is maintained by MITRE and released for public use. Extortion group activity is derived from this tracker’s own incident records, sourced from RansomLook under CC BY 4.0.