Threat Actors
Short answer: Evidence-based actor profiles — sponsorship, aliases, techniques, targets and timeline. Attribution is always confidence-tagged, never asserted as certainty.
Evidence: MITRE ATT&CK · CISA · vendor advisories · public attribution
- WIRTE Espionage + wiper cycles 2026-08-26 · Lebanon-linked
- Soft Cell Soft Cell — Middle East telecoms (China-linked) (Source: Researchers) 2026-08-26 · China
- Silent Librarian Phishing-focused espionage 2026-08-26 · Iran
- Putter Panda Telecom and aerospace theft 2026-08-26 · China
- Night Dragon Decade-long energy espionage 2026-08-26 · China
- Molerats Long-running espionage 2026-08-26 · Unknown
- Deep Panda Espionage + extortion later 2026-08-26 · China
- Camaro Dragon Espionage cluster 2026-08-26 · China
- APT9 Espionage 2026-08-26 · China
- APT8 Espionage 2026-08-26 · China
- APT7 Espionage 2026-08-26 · China
- APT6 Espionage cluster 2026-08-26 · China
- ZINC Crypto-targeted phishing 2026-08-26 · DPRK
- Wooly Typhoon Supply-chain espionage 2026-08-26 · China
- Winnti Dual-purpose espionage+extortion 2026-08-26 · China
- WildNeutron Supply-chain + mobile espionage 2026-08-26 · Unknown
- Turla Turla — Gov, embassies (Russia-linked) Source: CISA component. 2026-08-26 · Russia
- Transparent Tribe Crimson RAT campaigns 2026-08-26 · Pakistan
- TA505 TA505 — Retail/banks (Russia-linked) Source: Proofpoint. 2026-08-26 · Russia
- Strider Sofacy-adjacent 2026-08-26 · Unknown
- Sparkling Goblin Supply-chain intrusion 2026-08-26 · China?
- Sofacy Long-running espionage family 2026-08-26 · Russia
- SideWinder Three-headed espionage 2026-08-26 · Pakistan
- Pink Sandstorm Phishing + supply-chain 2026-08-26 · Iran
- Naikon Maritime espionage 2026-08-26 · China
- Patchwork Espionage tooling 2026-08-26 · India
- Orangeworm Medical device intrusions 2026-08-26 · Unknown
- Mustang Panda Mustang Panda (RedDelta) is a China-sponsored espionage actor active since 2017 that targets government organizations in Southeast Asia. Relevant because of sustained regional government-targeted espionage. (Source: Researchers, via OpenTrojan actor record) 2026-08-26 · China
- MuddyWater MuddyWater (Static Kitten) is an Iran-sponsored actor conducting Windows and Android espionage against Middle East government targets since 2018; documented in CISA advisory AA22-055A. (Source: CISA AA22-055A) 2026-08-26 · Iran
- Moses Staff Destructive attacks Israel 2026-08-26 · Iran
- menuPass Espionage + extortion later 2026-08-26 · China?
- Magic Hound Magic Hound (Cobalt Illusion) is an Iran-sponsored espionage actor conducting password-spray operations that have targeted energy and media sectors since 2014. (Source: Researchers, via OpenTrojan actor record) 2026-08-26 · Iran
- Lotus Blossom Diplomatic espionage 2026-08-26 · China
- Lemon Sandstorm Espionage 2026-08-26 · Iran
- LAPSUS$ LAPSUS$ is a criminal group using extortion and cloud-billing fraud against technology and crypto companies, active since 2021. Relevant as a financially motivated actor with repeated high-profile intrusions. (Source: Researchers) 2026-08-26 · Criminal
- Kimsuky Kimsuky (Velvet Chollima) is a DPRK-sponsored espionage actor conducting phishing-led operations against Korean and think-tank targets; documented in CISA advisory AA23-039A. (Source: CISA AA23-039A) 2026-08-26 · DPRK
- Ke3chang Long-running espionage 2026-08-26 · China
- Ivory Typhoon Silent espionage 2026-08-26 · China
- Indrik Spider Dridex + BitPaymer/WastedLocker 2026-08-26 · Russia
- GALLIUM Telecom supply-chain access 2026-08-26 · China
- Gorgon Group Espionage + destructive payloads 2026-08-26 · Pakistan
- Ginger Typhoon Long-term access espionage 2026-08-26 · China
- Gamaredon Gamaredon (Primitive Bear) is a Russia FSB-linked espionage actor focused on Ukrainian targets since 2013, primarily using phishing and commodity malware. (Source: Researchers, via OpenTrojan actor record) 2026-08-26 · Russia FSB-linked
- Forest Blizzard Fronton infrastructure espionage 2026-08-26 · Russia
- FIN7 FIN7 (Carbanak Group) is a Russia-based financially motivated criminal group using point-of-sale malware and Carbanak-style operations against retail and banking since 2014; documented by FireEye. (Source: FireEye) 2026-08-26 · Russia
- FIN12 Ransomware access facilitator 2026-08-26 · Russia
- Equation Group Extreme stealth espionage 2026-08-26 · US (attributed)
- Dragonfly ICS supply-chain intrusions (Havex) 2026-08-26 · Russia
- Dark Hotel Hotel WiFi spear-phishing 2026-08-26 · Unknown
- Crimson Sandstorm Cowboy/abyss campaigns 2026-08-26 · Iran
- Confucius Confucius — South Asia interests (South Asia-linked) (Source: Researchers) 2026-08-26 · South Asia
- Cobalt Group Banking fraud (ATM jackpotting) 2026-08-26 · Russia
- Chocolate Typhoon Espionage 2026-08-26 · China
- Cadet Blizzard Destructive info-ops attacks 2026-08-26 · Russia
- Cacao Typhoon Carrier espionage 2026-08-26 · China
- Blue Mockingbird RDP abuse + XMRig 2026-08-26 · Unknown
- BlackTech Espionage via router/office compromises 2026-08-26 · China
- Bitter Bitter — Pakistan interest groups (South Asia-linked) (Source: Researchers) 2026-08-26 · South Asia
- Aqua Blizzard Ukraine-focused sabotage 2026-08-26 · Russia
- APT5 Long-running espionage 2026-08-26 · PLA
- APT42 Spray-and-pray phishing espionage 2026-08-26 · Iran
- APT40 Maritime and energy espionage 2026-08-26 · China MSA
- APT39 APT39 — Telecom/IT supply chain (Iran-linked) (Source: FireEye) 2026-08-26 · Iran
- APT38 Lazarus economic/espionage unit 2026-08-26 · DPRK
- APT37 Espionage malware 2026-08-26 · DPRK
- APT36 Android trojans 2026-08-26 · Pakistan
- APT35 Phishing-focused espionage 2026-08-26 · Iran
- APT34 Gulf-target espionage 2026-08-26 · Iran
- APT33 Destructive-tied intrusions 2026-08-26 · Iran
- APT32 APT32 (OceanLotus) is a Vietnam-linked espionage actor active since 2012 that targets businesses across East Asia; documented by FireEye. (Source: FireEye) 2026-08-26 · Vietnam
- APT31 Email compromise espionage 2026-08-26 · China MSS
- APT30 Maritime defense-era espionage 2026-08-26 · China
- APT3 Espionage + supply-chain operator 2026-08-26 · PLA
- APT27 Long-active; logistics sector 2026-08-26 · China
- APT26 APT26 — Vietnam (China-linked) (Source: FireEye) 2026-08-26 · China
- APT25 APT25 — Latin America (LA-linked) (Source: FireEye) 2026-08-26 · LA
- APT24 APT24 — Multiple (Unknown-linked) (Source: FireEye) 2026-08-26 · Unknown
- APT23 APT23 — India (Pakistan-linked) (Source: FireEye) 2026-08-26 · Pakistan
- APT22 APT22 — Defense (China-linked) (Source: Researchers) 2026-08-26 · China
- APT21 APT21 — Tech (China-linked) (Source: FireEye) 2026-08-26 · China
- APT20 APT20 — Energy, HK (China-linked) (Source: FireEye T-APT) 2026-08-26 · China
- APT19 APT19 — Legal, IT (China-linked) (Source: FireEye) 2026-08-26 · China
- APT18 APT18 — Various (China-linked) (Source: FireEye) 2026-08-26 · China
- APT17 APT17 — Gov, tech (China-linked) (Source: FireEye) 2026-08-26 · China
- APT16 APT16 — Government (China-linked) (Source: FireEye) 2026-08-26 · China
- APT12 APT12 — Media, think tanks (China-linked) (Source: Researchers) 2026-08-26 · China
- APT10 APT10 — MSSPs, global (PLA MSI-linked) (Source: CISA AA21-356A) 2026-08-26 · PLA MSI
- APT1 APT1 — Defense contractors; 141 companies (PLA Unit 61398-linked) (Source: Mandiant report 2013) 2026-08-26 · PLA Unit 61398
- Andariel Andariel — South Korea (DPRK-linked) (Source: AhnLab/CrowdStrike) 2026-08-26 · DPRK
- Volt Typhoon Volt Typhoon is a China-linked espionage actor pre-positioning in U.S. critical-infrastructure networks since 2021, using living-off-the-land techniques and legitimate tools to maintain covert persistent access. 2026-08-26 · People's Republic of China (assessed)
- Scattered Spider (UNC3944) Scattered Spider (UNC3944) is a nimble, English-speaking cybercrime collective using SMS phishing and social engineering to gain identity-provider access, most notably breaching Okta tenants and large enterprises in 2022–2023. 2026-08-26 · Unattributed (cybercrime)
- Sandworm Sandworm is a GRU-aligned Russian unit specializing in destructive cyber-physical attacks — including the 2015 and 2016 Ukraine power-grid outages and the NotPetya wiper — rather than classic espionage. 2026-08-26 · Russian Federation (GRU, Unit 74455)
- LockBit Ransomware Operation LockBit was the dominant Ransomware-as-a-Service operation (2022–2024), known for world-record ransom demands and fast double encryption, until an international law-enforcement disruption seized its infrastructure in February 2024. 2026-08-26 · Unattributed (RaaS business model)
- Lazarus Group Lazarus Group is North Korea's cyber threat group behind the 2014 Sony breach and the 2017 WannaCry outbreak, now best known for large-scale cryptocurrency-exchange heists to fund state operations. 2026-08-26 · Democratic People's Republic of Korea (assessed)
- HAFNIUM HAFNIUM is a China-linked actor that exploited four Microsoft Exchange Server zero-days in March 2021 (ProxyLogon) to plant webshells on tens of thousands of on-premises mail servers. 2026-08-26 · People's Republic of China (assessed)
- Cl0p (CLOP) Ransomware Group Cl0p is a Russian-speaking ransomware group known for flash mass exploitation of zero-days — most notably the 2023 MOVEit Transfer campaign that breached hundreds of organizations through data theft and extortion. 2026-08-26 · Unattributed (Russian-speaking cybercrime)
- APT41 (Winnti) APT41 (Winnti) is a China-linked group active since at least 2007 that operates a technical-intelligence theft business model while conducting espionage and supply-chain attacks in the gaming, telecom and technology sectors. 2026-08-26 · People's Republic of China (assessed)
- APT29 (Cozy Bear / Midnight Blizzard) APT29 (Cozy Bear / Midnight Blizzard) is Russia's SVR-linked espionage group behind the SolarWinds SUNBURST supply-chain attack and sustained cloud identity hacking against government, tech and research organizations. 2026-08-26 · Russian Federation (SVR)
- APT28 (Fancy Bear) APT28 (Fancy Bear) is a Russia GRU-aligned threat group that has been compromising government, military and media targets since 2004, favoring spearphishing, credential theft and zero-day exploitation. 2026-08-26 · Russian Federation (GRU, Unit 26165)
Related: Campaigns · Industries