Threat Intelligence Directory
Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.
8,800+ entities tracked — APT groups, malware families, ransomware operators
✕ Clear filters1,027 entities
APT GROUP
UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026. The actor routed traffic through ExpressVPN and Mullvad exit nodes, utilizing over 200 IP addresses. Notably, several attacker hostnames, including a Kali Linux machine, were leaked during lateral movement, indicating hands-on-keyboard intrusion.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
UNC2529 is a well-resourced threat actor that conducted a global phishing campaign targeting various industries, utilizing tailored lures and sophisticated malware, including DOUBLEDRAG, DOUBLEDROP, and DOUBLEBACK. They compromised a legitimate domain to enhance their phishing efforts and employed at least 50 domains throughout the campaign. The actor demonstrated target research through personalized email addresses and subject lines, indicating a non-native English speaker. Their activities suggest a financial crime motive, with extensive use of obfuscation and fileless malware to evade detection.
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
UAT-7810 is an APT actor responsible for maintaining the LapDogs ORB network and developing custom malware, including the backdoors SHORTLEASH and LONGLEASH, as well as DOGLEASH and JARLEASH. They exploit known vulnerabilities in unpatched Ruckus wireless routers and have been observed using infrastructure to host malicious payloads across various hardware platforms. Forensic analysis has revealed their use of multiple IP addresses for hosting and deploying malware, including a test binary named LEASHTEST for functionality checks on MIPS devices. Talos assesses UAT-7810 as a China-nexus threat actor, providing infrastructure to secondary APTs while maintaining distinct objectives.
🇨🇳 CN
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
UAT-11795 is a sophisticated, Russian-speaking, financially motivated adversary conducting malicious campaigns targeting users in the U.S. and Europe since June 2025. The actor employs CastleStealer and Remcos RAT as alternative payload implants. Their operations indicate a focus on financial gain through targeted attacks.
🇷🇺 RU
Updated: 2026-08-03
View profile →APT GROUP
Launched in August 2025, the Scattered LAPSUS$ Hunters collective has rapidly established itself as one of the most formidable threats on today’s cybercriminal landscape. This alliance brings together three of the most notorious English-speaking cybercriminal groups: Scattered Spider, LAPSUS$ and ShinyHunters. In just a few months, this organization has multiplied spectacular attacks against leading companies, stealing billions of pieces of data and perfecting the art of digital extortion.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
JADEPUFFER is an agentic threat actor that executed a fully autonomous ransomware operation, leveraging a Large Language Model to automate the entire attack chain from initial access to data destruction. It exploited CVE-2025-3248 against an exposed Langflow instance for initial access, then compromised MinIO using default credentials and manipulated MySQL for privilege escalation. The operation culminated in the encryption of over 1,300 configuration records in Nacos, with the encryption key lost, rendering the data unrecoverable. JADEPUFFER exemplifies a shift towards machine-speed extortion, where traditional security models are outpaced by automated threats.
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
Jackpot Panda is a China-nexus state-sponsored APT primarily focused on cyber espionage against East and Southeast Asian entities, particularly in the online gambling sector and domestic security. They rapidly exploited CVE-2025-55182 using automated scanning, reconnaissance commands, and multi-vulnerability campaigns. Their activities have been linked to infrastructure associated with the exploitation of trojanized platforms and malware deployment, including SNOWLIGHT and VShell.
🇨🇳 CN
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
Hyadina is a threat actor that first emerged in March 2022, deploying its Monster ransomware variant primarily targeting 32-bit Windows systems while avoiding the CIS region. The group rebranded its ransomware as Beast in June 2024, enhancing its toolset to include support for Linux and VMware ESXi, and incorporating extensive use of NirSoft tools. The latest iteration, GodDamn, showcases advanced defensive evasion techniques, including the use of the PoisonX malicious driver component. Hyadina operates as a ransomware-as-a-service, collaborating with affiliates to execute attacks.
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
Cavern Manticore is an Iran-nexus APT primarily targeting Israeli organizations in the government and IT sectors, linked to the MOIS. The group employs a modular command-and-control framework built on a shared .NET foundation, utilizing multiple compilation formats to create an anti-analysis layer. Their operations demonstrate a high operational tempo and a disciplined approach to target selection, particularly during campaigns like "Operation Epic Fury." By decoupling core infrastructure from mission-specific modules, Cavern Manticore enhances operational agility while complicating detection efforts for defenders.
🇮🇷 IR
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
Armored Likho is an APT group targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. Their operations blend financially motivated campaigns with cyber-espionage, utilizing obfuscated, modular RATs and infostealers designed to evade dynamic analysis. They employ spear-phishing emails with deceptive themes to gain initial access, distributing malicious attachments that mimic legitimate content. Their toolkit includes BusySnake Stealer and AquilaRAT, with a focus on evolving TTPs and leveraging AI tools for payload generation.
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
Mysterious Elephant is an APT group active since 2023 that primarily targets government and foreign affairs entities across South Asia, especially Pakistan, Bangladesh, Sri Lanka, Nepal, and Afghanistan. In its early-2025 campaign it shifted toward spear-phishing and custom/customized tools—including the BabShell reverse shell and MemLoader HidenDesk/Edge loaders—to deploy RATs like Remcos and VRat, while also using WhatsApp-specific exfiltration tools to steal shared documents, images, and archives. The group shares code and infrastructure with other APT clusters (Origami Elephant, Confucius, SideWinder), reflecting ongoing tool reuse and collaboration among South Asian threat actors.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
TridentLocker is a ransomware group known for targeting organizations that manage high volumes of regulated or third-party data, including government services and telecom providers. They have claimed breaches of multiple victims, such as TMPartner, Sedgwick, and Advantage 360, often exfiltrating sensitive data before deploying ransomware. The group employs techniques such as stolen credentials, phishing, and exploitation of unpatched software to gain initial access and move laterally within networks. Their operations are characterized by high visibility postings on their leak portal, which include detailed victim profiles and countdown timers to create public pressure.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
The Gentlemen is a ransomware group that employs a dual-extortion strategy, encrypting sensitive files while exfiltrating critical business data to pressure victims into paying ransoms. Their operations leverage advanced techniques such as abusing legitimate utilities like PowerRun.exe for privilege escalation, using custom-built tools for defense evasion, and employing flexible encryption methods based on file size. The group targets medium to large organizations across various sectors, particularly in the Asia-Pacific region, and has demonstrated a high level of technical maturity and operational discipline. Their activities include systematic compromise of enterprise environments, mass account enumeration, and the use of encrypted channels for data exfiltration.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
SpaceBears is a ransomware group believed to be based in Moscow, Russia, that has taken credit for several high-profile cyberattacks while primarily operating as a Data Broker. They currently list eight organizations on their Data Leak Site, focusing on medium to small-sized targets. Their methods suggest a reliance on basic extortion strategies rather than sophisticated malware tactics, with no advanced techniques or indicators of ransomware detected.
🇷🇺 RU
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
Sinobi is a financially motivated ransomware group that employs data theft and extortion as primary tactics, operating a public-facing leak portal to pressure victims during ransom negotiations. The group utilizes techniques such as phishing, credential compromise, and exploitation of unpatched vulnerabilities for initial access, followed by data exfiltration using tools like RClone. Sinobi ransomware employs Curve-25519 and AES-128-CTR for file encryption, making recovery impossible without the attacker's private key. The group has been linked to significant breaches across various sectors, including automotive, legal, and nonprofit organizations.
Updated: 2026-08-03
View profile →APT GROUPhacktivism
SiegedSec, a hacktivist collective, emerged coincidentally just days before Russia’s invasion of Ukraine. Under the leadership of the hacktivist known as “YourAnonWolf,” the group swiftly gained strength, announcing an increasing number of victims after its inception. The group humorously self-identifies as “gay furry hackers” and is renowned for its comical slogans and the use of vulgar language. SiegedSec has affiliations with other hacker groups like GhostSec and typically consists of members aged between 18 and 26.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
ShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide range of targets, including businesses, organizations, and government agencies. ShinyHunters typically uses phishing attacks and exploit kits to gain access to victim networks, where they deploy malware to steal sensitive data, such as names, addresses, phone numbers, Social Security numbers, and credit card information.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
RansomHub is a rapidly growing ransomware group believed to be an updated version of the older Knight ransomware. They have been linked to attacks exploiting the Zerologon vulnerability to gain initial access. RansomHub has attracted former affiliates of the ALPHV ransomware group and operates as a Ransomware-as-a-Service with a unique affiliate prepayment model. The group has been active in extorting victims and leaking sensitive data to pressure for ransom payments.
APT GROUP
This group started operating during the first quarter of 2022. They published samples of alleged stolen data from companies on their site on Tor. It is unclear if they conducted the attacks themselves, or if they bought leaked databases from third parties.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
NullBulge is a cybercriminal threat group targeting AI and gaming focused entities. They weaponize code in publicly available repositories to distribute malware, including LockBit ransomware. The group claims to be motivated by a pro-art, anti-AI cause, but their activities indicate a financial focus. NullBulge uses obfuscated code in public repositories and malicious mods to target their victims.
Updated: 2026-08-03
View profile →APT GROUP
Cybereason Nocturnus describes Moses Staff as an Iranian hacker group, first spotted in October 2021. Their motivation appears to be to harm Israeli companies by leaking sensitive, stolen data.
🇮🇷 IRT1505.003T1021.002T1087.001
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
Mogilevich is a ransomware group known for claiming to breach organizations like Epic Games and Ireland's Department of Foreign Affairs, offering stolen data for sale without providing proof of the attacks. They operate as an extortion group, targeting high-profile victims and demanding payment for the data they claim to have stolen. Despite their claims, security researchers have noted that Mogilevich's tactics and website design suggest they may not be a sophisticated threat actor.
Updated: 2026-08-03
View profile →APT GROUP
An actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements.
T1136.003T1578.003T1589
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
Lamashtu is a financially motivated data-theft and extortion group that emerged in mid-April 2026, operating a Tor-hosted leak site (Lamashtu[.]Blog) with countdown timers, structured Breach Impact Reports, and proof-of-life thumbnails to pressure victims. The group has claimed 17+ victims across France, Romania, Thailand, Malaysia, Egypt, and the UAE within its first weeks of activity, targeting energy, pharmaceutical, retail, hospitality, and film sectors, with confirmed exfiltration totaling 760+ GB.
Updated: 2026-08-03
View profile →APT GROUPhacktivism
KelvinSecurity is a hacker group that has been active since at least 2015. They are known for their hacktivist and black hat activities, targeting public and private organizations globally. The group sells and leaks databases, documents, and access belonging to their victims, often on the dark web or their own platforms. They have been involved in attacks against various sectors, including telecommunications, political parties, and healthcare.
ES
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
Kazu is a financially motivated ransomware group known for employing a double extortion model, targeting sectors such as healthcare and government. The group has claimed responsibility for multiple high-profile breaches, including those of Manage My Health and the Defensoría del Pueblo de Colombia, exfiltrating sensitive data through techniques like exploiting unpatched vulnerabilities and credential reuse. Kazu has demanded ransoms ranging from $60,000 to $500,000, threatening public disclosure of stolen data if payments are not made. Their operations have primarily focused on entities in Latin America, Asia, and the Middle East, with a notable presence on dark web leak sites.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
Kairos is an extortion group that emerged with a data-leak site on 13 November 2024, claiming attacks against six organizations, primarily in the US healthcare sector. The group is financially motivated, demanding Bitcoin payments for the secure deletion of stolen files and threatening to leak data if victims do not comply. While no specific TTPs are publicly known, common techniques among extortion groups include phishing and scanning for exposed internet-facing devices. There is a potential link to a user on a Russian-language cybercriminal forum who shares a post-exploitation script, but attribution remains uncertain.
Updated: 2026-08-03
View profile →APT GROUPhacktivism
Handala is a pro-Palestinian hacktivist group that targets Israeli organizations, employing tactics such as phishing, data theft, extortion, and destructive attacks using custom wiper malware. The group utilizes a multi-stage loading process, including a Delphi-coded second-stage loader and an AutoIT injector, to deliver wiper malware that specifically targets Windows and Linux environments. Their phishing campaigns often exploit major events and critical vulnerabilities, masquerading as legitimate organizations to gain initial access. Handala operates a data leak site to publicize stolen data, although claims of successful attacks are sometimes disputed by targeted organizations.
PS
APT GROUPfinancialhigh
Funksec is a newly identified extortion group that has claimed 11 victims across various sectors, including media, IT, and education, operating a Tor-based DLS to centralize its ransomware activities. The group advertises a free DDoS tool and may develop its own ransomware binary, indicating significant technical capability. The DLS was likely created in late November to early December 2024, with the first advertisement titled “Funksec Ransomware” posted on 3 December 2024. Currently, there is limited publicly available information on Funksec's TTPs, and it is not known to be associated with any other threat groups.
APT GROUPfinancialhigh
FulcrumSec is a financially motivated data-theft-extortion group known for sophisticated ransomware attacks and double extortion tactics. They have exploited vulnerabilities such as hardcoded credentials and misconfigured cloud permissions to gain access to targets, including Novo Nordisk and Arup Group. Their operations involve extensive dwell time, with claims of spending months analyzing stolen data before contacting victims. FulcrumSec has demonstrated a targeted approach, often demanding ransoms that are strategically calculated based on the victim's financial profile.
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
DragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in India. They have also targeted websites affiliated with Israel and have shown support for pro-Palestinian causes. The group has been observed using defacement attacks, distributed denial-of-service attacks, and data leaks as part of their campaigns. DragonForce Malaysia has demonstrated an ability to adapt and evolve their tactics over time.
MY
APT GROUPfinancialhigh
Coinbase Cartel is a ransomware threat actor that emerged in September 2025, focusing on data exfiltration rather than encryption, and has claimed over 60 victims, primarily in the healthcare, technology, and transportation sectors. The group employs TTPs such as social engineering, credential harvesting, and collaboration with Initial Access Brokers to gain initial access. They operate a data leak site where they publish victim names and issue ransom demands, requiring payment via Bitcoin.
Updated: 2026-08-03
View profile →APT GROUP
The Belsen Group has exploited the CVE-2022-40684 vulnerability in Fortinet devices to compromise over 15,000 FortiGate firewalls, releasing detailed configurations and plaintext VPN credentials. Their leaked data, organized by country and IP address, primarily consists of configurations from FortiOS 7.0.6 and 7.2.1, which were the last vulnerable versions before patches were issued. Security researcher Kevin Beaumont confirmed that the group leveraged this vulnerability to gain unauthorized access and warned of potential exploitation of CVE-2024-55591 by similar threat actors. Fortinet has stated that the leaked data originates from older campaigns and not from any recent incidents.
Updated: 2026-08-03
View profile →APT GROUPfinancialhigh
AzzaSec is a hacktivist group that originated in Italy. Known for their pro-Palestine stance, they have been involved in various cyberattacks targeting Israel and pro-Israel countries. Additionally, AzzaSec has engaged in ransomware activities and has been known to collaborate with other cybercriminal groups.
IT
Updated: 2026-08-03
View profile →APT GROUPespionageadvanced
APT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th. The DLS bears a striking resemblance to that of LockBit, likely to leverage LockBit's reputation and attract potential affiliates. The rationale for this design mimicry is unclear, but it may be intended to signal operational parity with LockBit to inspire trust among low-level criminals. APT73 was formed by an alleged former LockBit affiliate following law enforcement's "Operation Cronos" in February 2024.
Updated: 2026-08-03
View profile →APT GROUP
Microsoft threat actor profile. Origin/Threat: India, Private sector offensive actor.
Updated: 2026-08-03
View profile →APT GROUP
Microsoft threat actor profile. Origin/Threat: Group in development.
Updated: 2026-08-03
View profile →APT GROUP
Microsoft threat actor profile from the public naming mapping feed.
Updated: 2026-08-03
View profile →APT GROUP
Microsoft threat actor profile. Origin/Threat: China.
🇨🇳 CN
Updated: 2026-08-03
View profile →APT GROUP
Microsoft threat actor profile. Origin/Threat: Lebanon.
LBT1595.002T1190T1105
Updated: 2026-08-03
View profile →