Critical Infrastructure Cybersecurity Framework
Threat Intelligence
HomeThreat Intelligence

Threat Intelligence

Comprehensive profiles of 171 advanced persistent threat (APT) groups and their tactics, techniques, and procedures (TTPs). Understanding adversary behavior is critical for effective defense.

Total Groups

171

Active Groups

171

Countries

20

Target Sectors

51

Showing 12 of 171 threat actors
G0018Active

admin@338

China

admin@338 is a China-based cyber threat group that has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and trade policy.

Since 2013
🎯 Unknown

Target Sectors:

GovernmentFinancial

Associated Techniques:

G1030Active

Agrius

Iran

Also known as:

Pink SandstormAMERICIUMAgonizing SerpensBlackShadow

Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.

Since 2020
🎯 Unknown

Target Sectors:

GovernmentTechnology

Associated Techniques:

G0130Active

Ajax Security Team

Iran

Also known as:

Operation Woolen-GoldfishAjaxTMRocket KittenFlying Kitten

Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran.

Since 2010
🎯 Unknown

Target Sectors:

DefenseGovernment

Associated Techniques:

G1024Active

Akira

Unknown

Also known as:

GOLD SAHARAPUNK SPIDERHowling Scorpius

Akira is a ransomware variant and ransomware deployment entity active since at least March 2023.

Since 2023
🎯 Unknown

Target Sectors:

HealthcareFinancialManufacturing

Associated Techniques:

G1031Active

Akira Team

Unknown

Akira Team is a ransomware group that has been active since at least March 2023, targeting organizations across various sectors.

Since 2023
🎯 Unknown

Target Sectors:

HealthcareFinancialManufacturingTechnology

Associated Techniques:

G1000Active

ALLANITE

Russia

Also known as:

Palmetto Fusion

ALLANITE is a suspected Russian cyber espionage group that has primarily targeted the electric utility sector within the United States and United Kingdom.

Since 2017
🎯 Unknown

Target Sectors:

Energy

Associated Techniques:

G0138Active

Andariel

North Korea

Also known as:

Silent ChollimaPLUTONIUMOnyx Sleet

Andariel is a North Korean state-sponsored threat group that has been active since at least 2009, focusing on South Korean government agencies and military organizations.

Since 2009
🎯 Unknown

Target Sectors:

GovernmentDefenseFinancial

Associated Techniques:

G1007Active

Aoqin Dragon

China

Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013, targeting government, education, and telecommunication organizations.

Since 2013
🎯 Unknown

Target Sectors:

GovernmentEducationTelecommunications

Associated Techniques:

G1049Active

AppleJeus

North Korea

Also known as:

Gleaming PiscesCitrine SleetUNC1720

AppleJeus is a North Korean state-sponsored threat group primarily targeting the cryptocurrency industry.

Since 2018
🎯 Unknown

Target Sectors:

FinancialCryptocurrency

Associated Techniques:

G1028Active

APT-C-23

Palestine

Also known as:

MantisArid ViperDesert FalconTwo-tailed Scorpion

APT-C-23 is a threat group that has been active since at least 2014, primarily focused on the Middle East.

Since 2014
🎯 Unknown

Target Sectors:

GovernmentDefense

Associated Techniques:

G0099Active

APT-C-36

South America

Also known as:

Blind Eagle

APT-C-36 is a suspected South America espionage group that has been active since at least 2018.

Since 2018
🎯 Unknown

Target Sectors:

GovernmentFinancialEnergy

Associated Techniques:

G0006Active

APT1

China

Also known as:

Comment CrewComment GroupComment Panda

APT1 is a Chinese threat group attributed to the 2nd Bureau of the People's Liberation Army (PLA) General Staff Department's 3rd Department, Unit 61398.

Since 2006
🎯 Unknown

Target Sectors:

TechnologyAerospaceEnergyFinancial

Associated Techniques:

Threat Actor Distribution

China57

33.3% of total

Unknown31

18.1% of total

Russia22

12.9% of total

Iran21

12.3% of total

North Korea11

6.4% of total

Middle East4

2.3% of total

Pakistan4

2.3% of total

Palestine3

1.8% of total

By using this website, you agree to our legal documents. Please review our Privacy Policy, Terms of Use, and Accessibility Statement in the footer.