313 Team
ID: 313-TEAM
|
RECORDS: 7
Year Established 2019 Attribution Iran (IRGC-Linked) Motivation Hacktivism, Religious, Anti-Israel Modus Operandi (MO) Web defacement, DDoS, data leaks targeting Israeli and Western entities Primary Aliases…
[ VIEW PROFILE ]
8Base
ID: 8BASE
|
RECORDS: 0
Year Established 2022 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion ransomware, Phobos ransomware variant, aggressive victim shaming Primary Aliases 8base 8Base…
[ VIEW PROFILE ]
Akatsuki Cyber Team
ID: AKATSUKI-CYBER-TEAM
|
RECORDS: 1
CLASSIFIED: No public dossier available at this time.
[ VIEW PROFILE ]
Akira Ransomware
ID: AKIRA-RANSOMWARE
|
RECORDS: 0
Year Established 2023 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion RaaS, Cisco VPN exploitation, retro-aesthetic branding Primary Aliases Akira Akira Ransomware…
[ VIEW PROFILE ]
ALPHV (BlackCat)
ID: ALPHV-BLACKCAT
|
RECORDS: 0
Year Established 2021 Attribution Russia Motivation Financial Modus Operandi (MO) RaaS, Rust-based cross-platform ransomware, triple extortion, aggressive media relations Primary Aliases BlackCat, ALPHV, Noberus ALPHV,…
[ VIEW PROFILE ]
Andariel
ID: ANDARIEL
|
RECORDS: 0
Year Established 2015 Attribution North Korea (RGB Bureau 121) Motivation Financial, Espionage, Ransomware Modus Operandi (MO) Healthcare ransomware, defence contractor espionage, cryptocurrency theft Primary Aliases…
[ VIEW PROFILE ]
AnonGhost
ID: ANONGHOST
|
RECORDS: 0
Year Established 2012 Attribution Unknown (North African / Middle Eastern Suspected) Motivation Hacktivism, Pro-Palestinian, Anti-Israel, Political Modus Operandi (MO) Web defacement, DDoS, mobile app vulnerabilities,…
[ VIEW PROFILE ]
Anonymous Sudan
ID: ANONYMOUS-SUDAN
|
RECORDS: 0
Year Established 2023 Attribution Sudan / Russia (Pro-Russian Suspected) Motivation Hacktivism, Pro-Russian, Anti-Western, Religious Modus Operandi (MO) High-volume DDoS, cloud platform attacks, critical infrastructure targeting…
[ VIEW PROFILE ]
APT31
ID: APT31
|
RECORDS: 0
Year Established 2010 Attribution China (MSS) Motivation Espionage, Political Intelligence Modus Operandi (MO) Spear-phishing, credential theft, journalist and dissident targeting, political campaign interference Primary Aliases…
[ VIEW PROFILE ]
APT32 (OceanLotus)
ID: APT32-OCEANLOTUS
|
RECORDS: 0
Year Established 2014 Attribution Vietnam (Ministry of Public Security) Motivation Espionage, Corporate Intelligence, Dissident Surveillance Modus Operandi (MO) Spear-phishing, watering hole attacks, custom malware, targeting…
[ VIEW PROFILE ]
APT40
ID: APT40
|
RECORDS: 0
Year Established 2013 Attribution China (MSS Hainan State Security Department) Motivation Espionage, Maritime and Naval Intelligence Modus Operandi (MO) Maritime and naval sector targeting, spear-phishing,…
[ VIEW PROFILE ]
APT41
ID: APT41
|
RECORDS: 1
Year Established 2012 Attribution China (MSS) Motivation Espionage, Financial Modus Operandi (MO) Dual-track espionage and financial crime, supply chain attacks, zero-day exploitation, video game industry…
[ VIEW PROFILE ]
BABAYO EROR SYSTEM
ID: BABAYO-EROR-SYSTEM
|
RECORDS: 1
Year Established 2023 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database extraction, regional government targeting Primary Aliases BABAYO ERROR SYSTEM, BES BABAYO…
[ VIEW PROFILE ]
BianLian
ID: BIANLIAN
|
RECORDS: 0
Year Established 2022 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Data theft extortion pivot (former ransomware), healthcare and critical infrastructure targeting Primary…
[ VIEW PROFILE ]
Black Basta
ID: BLACK-BASTA
|
RECORDS: 0
Year Established 2022 Attribution Russia (Conti Successor) Motivation Financial Modus Operandi (MO) RaaS, double extortion, social engineering via Microsoft Teams, Conti-linked operators Primary Aliases Black…
[ VIEW PROFILE ]
Black Shadow
ID: BLACK-SHADOW
|
RECORDS: 0
Year Established 2020 Attribution Iran (IRGC-linked) Motivation Hacktivism, Geopolitical, Disruption Modus Operandi (MO) Data exfiltration, public data leaks, anti-Israel operations, website defacement Primary Aliases BlackShadow…
[ VIEW PROFILE ]
BlueNoroff
ID: BLUENOROFF
|
RECORDS: 0
Year Established 2016 Attribution North Korea (RGB Bureau 121) Motivation Financial, Cryptocurrency Theft Modus Operandi (MO) SWIFT banking attacks, cryptocurrency exchange targeting, venture capital and…
[ VIEW PROFILE ]
Charming Kitten
ID: CHARMING-KITTEN
|
RECORDS: 0
Year Established 2014 Attribution Iran (IRGC) Motivation Espionage, Surveillance, Dissident Monitoring Modus Operandi (MO) Fake social media personas, journalist and researcher targeting, phishing via WhatsApp…
[ VIEW PROFILE ]
Cobalt Group
ID: COBALT-GROUP
|
RECORDS: 0
Year Established 2016 Attribution Russia/Eastern Europe Motivation Financial Modus Operandi (MO) ATM jackpotting, SWIFT banking attacks, spear-phishing financial institutions, Cobalt Strike abuse Primary Aliases GOLD…
[ VIEW PROFILE ]
coinbasecartel
ID: COINBASECARTEL
|
RECORDS: 1
Year Established 2023 Attribution Unknown Motivation Financial, Cryptocurrency Fraud Modus Operandi (MO) Cryptocurrency exchange targeting, phishing, credential theft, crypto asset theft Primary Aliases Coinbase Cartel…
[ VIEW PROFILE ]
Cozy Bear (APT29)
ID: COZY-BEAR-APT29
|
RECORDS: 0
Year Established 2008 Attribution Russia (SVR/FSB) Motivation Espionage, Intelligence Collection Modus Operandi (MO) Spear-phishing, supply chain attacks, cloud exploitation, diplomatic and government targeting Primary Aliases…
[ VIEW PROFILE ]
Cyb3r Drag0nz
ID: CYB3R-DRAG0NZ
|
RECORDS: 0
Year Established 2022 Attribution Southeast Asia (Suspected) Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, credential dumping, multi-country targeting Primary Aliases Cyber Dragonz, C3D Cyb3r…
[ VIEW PROFILE ]
Cyber Islamic Resistance
ID: CYBER-ISLAMIC-RESISTANCE
|
RECORDS: 0
Year Established 2023 Attribution Unknown (Middle Eastern Suspected) Motivation Hacktivism, Religious, Pro-Palestinian, Anti-Israel Modus Operandi (MO) DDoS attacks, web defacement, anti-Israel and anti-Western operations Primary…
[ VIEW PROFILE ]
Cyber Team Indonesia
ID: CYBER-TEAM-INDONESIA
|
RECORDS: 6
Year Established 2021 Attribution Indonesia Motivation Hacktivism, Nationalism, Notoriety Modus Operandi (MO) Web defacement, database extraction, targeting domestic and international e-commerce platforms Primary Aliases CTI,…
[ VIEW PROFILE ]
CyberAv3ngers
ID: CYBERAV3NGERS
|
RECORDS: 1
Year Established 2020 Attribution Iran (IRGC) Motivation Hacktivism, Geopolitical, Critical Infrastructure Disruption Modus Operandi (MO) ICS/SCADA targeting, water utility attacks, anti-Israel and anti-US operations Primary…
[ VIEW PROFILE ]
CyberLeeks
ID: CYBERLEEKS
|
RECORDS: 1
Year Established 2026 Attribution Global (Decentralized / Anonymous) Motivation Anti-Corporate Ideology, Clout, Entertainment Industry Data Leaks Modus Operandi (MO) Supply chain exfiltration, social engineering, Telegram…
[ VIEW PROFILE ]
Dark Angels
ID: DARK-ANGELS
|
RECORDS: 0
Year Established 2022 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Big game hunting, high-value ransomware, quiet negotiation tactics Primary Aliases Dark Angels…
[ VIEW PROFILE ]
Dark Pink
ID: DARK-PINK
|
RECORDS: 0
Year Established 2021 Attribution Unknown (Southeast Asian Suspected) Motivation Espionage Modus Operandi (MO) Spear-phishing, USB-based propagation, government and military targeting in ASEAN region Primary Aliases…
[ VIEW PROFILE ]
Dark Storm Team
ID: DARK-STORM-TEAM
|
RECORDS: 3
Year Established 2023 Attribution Pro-Palestinian (International) Motivation Hacktivism, Pro-Palestinian, Anti-Israel, Anti-Western Modus Operandi (MO) DDoS attacks, data leaks, targeting critical infrastructure and media organisations Primary…
[ VIEW PROFILE ]
DarkHotel
ID: DARKHOTEL
|
RECORDS: 0
Year Established 2007 Attribution South Korea (Suspected) Motivation Espionage, Corporate Intelligence Modus Operandi (MO) Hotel Wi-Fi attacks, spear-phishing senior executives, zero-day exploitation Primary Aliases Dubnium,…
[ VIEW PROFILE ]
DarkSide
ID: DARKSIDE
|
RECORDS: 0
Year Established 2020 Attribution Russia Motivation Financial Modus Operandi (MO) RaaS, double extortion, critical infrastructure attacks, Colonial Pipeline shutdown Primary Aliases Carbon Spider (partial), BlackMatter…
[ VIEW PROFILE ]
Deadlock Ransomware
ID: DEADLOCK-RANSOMWARE
|
RECORDS: 1
Year Established 2024 Attribution Unknown Motivation Financial Modus Operandi (MO) Double-extortion ransomware, targeting mid-market enterprises Primary Aliases Deadlock Deadlock Ransomware is an emerging ransomware operation…
[ VIEW PROFILE ]
Dewata Blackhat
ID: DEWATA-BLACKHAT
|
RECORDS: 4
Year Established 2022 Attribution Indonesia (Bali-origin Suspected) Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping, regional government targeting Primary Aliases DewataBlackhat, Dewata BH…
[ VIEW PROFILE ]
DragonForce Ransomware
ID: DRAGONFORCE-RANSOMWARE
|
RECORDS: 1
Year Established 2023 Attribution Malaysia (Suspected) Motivation Financial, Hacktivism (Origins) Modus Operandi (MO) RaaS, LockBit/Conti-based ransomware, pivot from hacktivism to criminal ransomware operation Primary Aliases…
[ VIEW PROFILE ]
Earth Krahang
ID: EARTH-KRAHANG
|
RECORDS: 0
Year Established 2022 Attribution China (MSS Affiliated) Motivation Espionage, Government Intelligence Collection Modus Operandi (MO) Compromised government infrastructure for lateral attacks, spear-phishing, VPN exploitation, Southeast…
[ VIEW PROFILE ]
Equation Group
ID: EQUATION-GROUP
|
RECORDS: 0
Year Established 2001 Attribution USA (NSA/TAO) Motivation Espionage, Critical Infrastructure Access, Global Signals Intelligence Modus Operandi (MO) HDD firmware implants, air-gap bridging, nation-state-level zero-days, PRISM-adjacent…
[ VIEW PROFILE ]
Fancy Bear (APT28)
ID: FANCY-BEAR-APT28
|
RECORDS: 0
Year Established 2004 Attribution Russia (GRU Unit 26165 & 74455) Motivation Espionage, Influence Operations, Election Interference Modus Operandi (MO) Credential phishing, X-Agent/Sofacy malware, election infrastructure…
[ VIEW PROFILE ]
FEMBOYSec
ID: FEMBOYSEC
|
RECORDS: 4
Year Established 2023 Attribution Unknown (Western, English-Speaking Suspected) Motivation Hacktivism, Notoriety, LGBTQ+ Adjacent Modus Operandi (MO) Web defacement, data leaks, edgelord-style provocative branding Primary Aliases…
[ VIEW PROFILE ]
FIN7
ID: FIN7
|
RECORDS: 0
Year Established 2015 Attribution Russia/Ukraine Motivation Financial Modus Operandi (MO) Point-of-sale malware, spear-phishing restaurant/hospitality chains, CARBANAK malware, ransomware pivot Primary Aliases Carbanak Group, Navigator Group,…
[ VIEW PROFILE ]
Flax Typhoon
ID: FLAX-TYPHOON
|
RECORDS: 0
Year Established 2021 Attribution China (MSS) Motivation Espionage, Persistent Access Modus Operandi (MO) Living-off-the-land techniques, VPN exploitation, Taiwan-focused espionage Primary Aliases Ethereal Panda, RedJuliett Flax…
[ VIEW PROFILE ]
Gamaredon
ID: GAMAREDON
|
RECORDS: 0
Year Established 2013 Attribution Russia (FSB) Motivation Espionage, Sabotage (Ukraine-focused) Modus Operandi (MO) Massive-scale Ukraine targeting, phishing, USB worms, template injection, near-daily attack operations Primary…
[ VIEW PROFILE ]
GANOSEC Team
ID: GANOSEC-TEAM
|
RECORDS: 0
Year Established 2022 Attribution Indonesia Motivation Hacktivism, Nationalism, Pro-Palestinian Modus Operandi (MO) Web defacement, DDoS, database dumping, coordinated campaigns Primary Aliases Ganosec, GANO Security Team…
[ VIEW PROFILE ]
Garuda Kernel Error System
ID: GARUDA-KERNEL-ERROR-SYSTEM
|
RECORDS: 2
Year Established 2024 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database exploitation Primary Aliases GKES, Garuda Kernel Garuda Kernel Error System (GKES)…
[ VIEW PROFILE ]
GhostSec
ID: GHOSTSEC
|
RECORDS: 0
Year Established 2015 Attribution Unknown (International) Motivation Hacktivism, Anti-ISIS, Later Pro-Palestinian, Financial (Ransomware pivot) Modus Operandi (MO) Counter-terrorism operations, website takedowns, data leaks, ransomware deployment…
[ VIEW PROFILE ]
Gorgon Group
ID: GORGON-GROUP
|
RECORDS: 0
Year Established 2018 Attribution Pakistan Motivation Espionage, Financial Crime Modus Operandi (MO) Dual-track espionage and cybercrime, RevengeRAT delivery, targeting Western governments and financial institutions Primary…
[ VIEW PROFILE ]
GUNRA
ID: GUNRA
|
RECORDS: 1
Year Established 2024 Attribution Unknown Motivation Financial Modus Operandi (MO) Double-extortion ransomware, targeting corporate networks, data leak threats Primary Aliases GUNRA Ransomware GUNRA is an…
[ VIEW PROFILE ]
Hafnium
ID: HAFNIUM
|
RECORDS: 0
Year Established 2021 Attribution China (MSS) Motivation Espionage Modus Operandi (MO) Microsoft Exchange zero-day exploitation (ProxyLogon), web shell deployment, US defence contractor and NGO targeting…
[ VIEW PROFILE ]
HANDALA
ID: HANDALA
|
RECORDS: 4
Year Established 2023 Attribution Iran (Suspected) Motivation Hacktivism, Pro-Palestinian, Anti-Israel Modus Operandi (MO) Destructive wiper attacks, data leaks, psychological operations against Israeli targets Primary Aliases…
[ VIEW PROFILE ]
HMEI7
ID: HMEI7
|
RECORDS: 0
Year Established 2008 Attribution Iran (Suspected) Motivation Hacktivism, Pro-Palestinian, Anti-Israel, Religious Modus Operandi (MO) Mass web defacement campaigns, one of the longest-running defacement groups globally…
[ VIEW PROFILE ]
Hunters International
ID: HUNTERS-INTERNATIONAL
|
RECORDS: 0
Year Established 2023 Attribution Unknown Motivation Financial Modus Operandi (MO) RaaS, data theft extortion, suspected Hive ransomware successor Primary Aliases Hunters Hunters International is a…
[ VIEW PROFILE ]
INC Ransomware
ID: INC-RANSOMWARE
|
RECORDS: 1
Year Established 2023 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion ransomware, healthcare and education targeting, Citrix and VPN exploitation Primary Aliases…
[ VIEW PROFILE ]
Indian Cyber Force
ID: INDIAN-CYBER-FORCE
|
RECORDS: 0
Year Established 2022 Attribution India Motivation Hacktivism, Nationalism, Anti-Pakistan, Anti-China Modus Operandi (MO) Web defacement, DDoS, database leaks targeting Pakistani and Chinese entities Primary Aliases…
[ VIEW PROFILE ]
INDOHAXSEC
ID: INDOHAXSEC
|
RECORDS: 1
Year Established 2023 Attribution Indonesia Motivation Hacktivism, Geopolitical Modus Operandi (MO) DDoS attacks, web defacement, data leaks, pro-Palestinian operations Primary Aliases IndoHaxSec, Indonesian Haxsec INDOHAXSEC…
[ VIEW PROFILE ]
Infrastructure Destruction Squad
ID: INFRASTRUCTURE-DESTRUCTION-SQUAD
|
RECORDS: 1
Year Established 2024 Attribution Unknown (Pro-Russian Suspected) Motivation Hacktivism, Sabotage, Geopolitical Modus Operandi (MO) ICS/SCADA targeting, critical infrastructure disruption, destructive attacks Primary Aliases IDS, Infra…
[ VIEW PROFILE ]
JADEPUFFER
ID: JADEPUFFER
|
RECORDS: 1
Year Established 2025 Attribution Unknown (AI-Assisted Operations) Motivation Financial, Espionage Modus Operandi (MO) AI-augmented ransomware development, autonomous attack chain execution, adaptive evasion Primary Aliases JADE…
[ VIEW PROFILE ]
JundAlNabi
ID: JUNDALNABI
|
RECORDS: 3
Year Established 2024 Attribution Pakistan Motivation Hacktivism, Religious, Pro-Palestinian Modus Operandi (MO) DDoS, web defacement, data exfiltration Primary Aliases Jund Al Nabi, JAN JundAlNabi is…
[ VIEW PROFILE ]
K3LLLEAKERS
ID: K3LLLEAKERS
|
RECORDS: 1
K3LLLEAKERS is a hacktivist and data breach entity known for leaking government database archives and targeting public sector infrastructure in Southeast Asia.
[ VIEW PROFILE ]
Karakurt
ID: KARAKURT
|
RECORDS: 0
Year Established 2021 Attribution Russia (Conti Group Affiliated) Motivation Financial Modus Operandi (MO) Data theft extortion without encryption, Conti/Diavol-linked infrastructure Primary Aliases Karakurt Team, Karakurt…
[ VIEW PROFILE ]
KARAWANG ERROR SYSTEM
ID: KARAWANG-ERROR-SYSTEM-2
|
RECORDS: 1
Year Established 2024 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping Primary Aliases KES, Karawang Error KARAWANG ERROR SYSTEM (KES) is…
[ VIEW PROFILE ]
Keymous
ID: KEYMOUS
|
RECORDS: 0
Year Established 2022 Attribution Unknown (North African Suspected) Motivation Hacktivism, Financial Modus Operandi (MO) Database leaks, credential theft, dark web data sales Primary Aliases Keymous+,…
[ VIEW PROFILE ]
Killnet
ID: KILLNET
|
RECORDS: 0
Year Established 2022 Attribution Russia (Pro-Russian) Motivation Hacktivism, Pro-Russian, Anti-NATO Modus Operandi (MO) DDoS attacks, coordinating pro-Russian hacktivist alliances, propaganda operations Primary Aliases KillNet, Kill…
[ VIEW PROFILE ]
Kimsuky (APT43)
ID: KIMSUKY-APT43
|
RECORDS: 0
Year Established 2012 Attribution North Korea (RGB) Motivation Espionage, Policy Intelligence, Nuclear Monitoring Modus Operandi (MO) Spear-phishing, fake think tank personas, Korean peninsula policy researcher…
[ VIEW PROFILE ]
Lapsus$
ID: LAPSUS
|
RECORDS: 0
Year Established 2021 Attribution UK / Brazil / International (Teenagers) Motivation Notoriety, Financial Modus Operandi (MO) Social engineering, SIM swapping, insider recruitment, targeting major tech…
[ VIEW PROFILE ]
Laundry Bear APT
ID: LAUNDRY-BEAR-APT
|
RECORDS: 0
Year Established 2024 Attribution Russia (Suspected) Motivation Espionage, Information Operations Modus Operandi (MO) Supply chain compromise, credential theft, intelligence gathering Primary Aliases Laundry Bear, UNC5812…
[ VIEW PROFILE ]
Lazarus Group
ID: LAZARUS-GROUP
|
RECORDS: 0
Year Established 2009 Attribution North Korea (RGB Bureau 121) Motivation Financial, Espionage, Sabotage Modus Operandi (MO) Cryptocurrency heists, SWIFT banking attacks, supply chain compromise, espionage,…
[ VIEW PROFILE ]
LockBit
ID: LOCKBIT
|
RECORDS: 0
Year Established 2019 Attribution Russia (Suspected) Motivation Financial Modus Operandi (MO) RaaS, most prolific ransomware of its era, aggressive affiliate model, automated propagation Primary Aliases…
[ VIEW PROFILE ]
LulzSec Indonesia
ID: LULZSEC-INDONESIA
|
RECORDS: 0
Year Established 2020 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping, adoption of LulzSec branding Primary Aliases LulzSecIndo LulzSec Indonesia is…
[ VIEW PROFILE ]
LunarisSec
ID: LUNARISSEC
|
RECORDS: 1
Year Established 2023 Attribution Unknown Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping, multi-country targeting Primary Aliases Lunaris Security, Lunaris LunarisSec is a…
[ VIEW PROFILE ]
Magecart
ID: MAGECART
|
RECORDS: 0
Year Established 2015 Attribution Multiple Groups (International) Motivation Financial Modus Operandi (MO) Web skimming, JavaScript injection into e-commerce checkout pages, payment card theft at scale…
[ VIEW PROFILE ]
Medusa Ransomware
ID: MEDUSA-RANSOMWARE
|
RECORDS: 0
Year Established 2021 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion RaaS, education and healthcare targeting, public countdown timers Primary Aliases Medusa,…
[ VIEW PROFILE ]
Midnight Blizzard (Nobelium)
ID: MIDNIGHT-BLIZZARD-NOBELIUM
|
RECORDS: 0
Year Established 2018 Attribution Russia (SVR) Motivation Espionage Modus Operandi (MO) Supply chain attacks, OAuth abuse, cloud environment targeting, diplomatic and government espionage Primary Aliases…
[ VIEW PROFILE ]
Mint Sandstorm (APT35)
ID: MINT-SANDSTORM-APT35
|
RECORDS: 0
Year Established 2014 Attribution Iran (IRGC) Motivation Espionage, Influence Operations, Journalist and Researcher Targeting Modus Operandi (MO) Spear-phishing, fake conference invitations, credential harvesting, targeting journalists…
[ VIEW PROFILE ]
MuddyWater
ID: MUDDYWATER
|
RECORDS: 0
Year Established 2017 Attribution Iran (MOIS) Motivation Espionage, Influence Operations Modus Operandi (MO) Spear-phishing, PowerShell-based malware, Middle East and European government targeting Primary Aliases Static…
[ VIEW PROFILE ]
Mustang Panda
ID: MUSTANG-PANDA
|
RECORDS: 0
Year Established 2012 Attribution China (MSS) Motivation Espionage, Political Intelligence Modus Operandi (MO) Spear-phishing with PlugX malware, USB propagation, targeting Southeast Asian governments and NGOs…
[ VIEW PROFILE ]
N1ghtSp1d3rz
ID: N1GHTSP1D3RZ
|
RECORDS: 1
Year Established 2023 Attribution Unknown (Southeast Asian Suspected) Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database leaks, multi-sector targeting Primary Aliases Night Spiderz, NightSpiders…
[ VIEW PROFILE ]
NoName057(16)
ID: NONAME057
|
RECORDS: 30
Year Established 2022 Attribution Russia (Pro-Russian) Motivation Hacktivism, Pro-Russian, Anti-NATO Modus Operandi (MO) Coordinated DDoS via volunteer botnet (DDoSia tool), targeting NATO and Ukraine-supporting nations…
[ VIEW PROFILE ]
Nullsec Nigeria
ID: NULLSEC-NIGERIA
|
RECORDS: 1
Year Established 2024 Attribution Nigeria Motivation Financial, Hacktivism Modus Operandi (MO) Data extortion, fake breach claims, social media pressure tactics Primary Aliases NullSec NG, NullSec…
[ VIEW PROFILE ]
OilRig
ID: OILRIG
|
RECORDS: 1
Year Established 2014 Attribution Iran (MOIS/IRGC) Motivation Espionage, Persistent Access Modus Operandi (MO) Spear-phishing, custom malware (POWRUNER, BONDUPDATER), Middle East government and energy sector targeting…
[ VIEW PROFILE ]
Panoc Team
ID: PANOC-TEAM
|
RECORDS: 0
Year Established 2023 Attribution Unknown Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping, low-sophistication opportunistic attacks Primary Aliases Panic Team Panoc Team is…
[ VIEW PROFILE ]
Patchwork APT
ID: PATCHWORK-APT
|
RECORDS: 0
Year Established 2015 Attribution India (Suspected) Motivation Espionage Modus Operandi (MO) Spear-phishing, BADNEWS malware, targeting Pakistan, China, and Southeast Asian governments Primary Aliases Dropping Elephant,…
[ VIEW PROFILE ]
People's Cyber Army
ID: PEOPLES-CYBER-ARMY
|
RECORDS: 0
Year Established 2022 Attribution Russia (Pro-Russian) Motivation Hacktivism, Pro-Russian, Anti-Ukraine, Anti-NATO Modus Operandi (MO) DDoS attacks, coordinating volunteer cyber operations, targeting NATO and Ukraine-supporting entities…
[ VIEW PROFILE ]
Pioneer Kitten
ID: PIONEER-KITTEN
|
RECORDS: 0
Year Established 2017 Attribution Iran (IRGC Contracted) Motivation Espionage, Financial (Ransomware Collaboration) Modus Operandi (MO) VPN and firewall zero-day exploitation, selling network access, ransomware partnership…
[ VIEW PROFILE ]
Play Ransomware
ID: PLAY-RANSOMWARE
|
RECORDS: 0
Year Established 2022 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion ransomware, Exchange server exploitation, no negotiation policy Primary Aliases PlayCrypt, Play…
[ VIEW PROFILE ]
Predatory Sparrow
ID: PREDATORY-SPARROW
|
RECORDS: 0
Year Established 2021 Attribution Israel (Suspected) Motivation Sabotage, Geopolitical, Counter-Iran Modus Operandi (MO) Destructive ICS/SCADA attacks against Iranian infrastructure, wiper malware, psychological operations Primary Aliases…
[ VIEW PROFILE ]
Qilin
ID: QILIN
|
RECORDS: 0
Year Established 2023 Attribution China (Suspected) Motivation Financial Modus Operandi (MO) Ransomware-as-a-Service (RaaS), double-extortion, healthcare and critical infrastructure targeting Primary Aliases Agenda Ransomware, Qilin Ransomware…
[ VIEW PROFILE ]
RansomHouse
ID: RANSOMHOUSE
|
RECORDS: 1
Year Established 2021 Attribution Unknown Motivation Financial Modus Operandi (MO) Data theft extortion without ransomware, marketplace model for stolen data, corporate targeting Primary Aliases Ransomhouse,…
[ VIEW PROFILE ]
RansomHub
ID: RANSOMHUB
|
RECORDS: 0
Year Established 2024 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) RaaS, aggressive affiliate recruitment, targeting critical infrastructure Primary Aliases Ransomhub RansomHub is…
[ VIEW PROFILE ]
Red Apollo (APT10)
ID: RED-APOLLO-APT10
|
RECORDS: 0
Year Established 2009 Attribution China (MSS) Motivation Espionage, Intellectual Property Theft Modus Operandi (MO) Managed service provider (MSP) compromise, supply chain attacks, global IP theft…
[ VIEW PROFILE ]
REvil (Sodinokibi)
ID: REVIL-SODINOKIBI
|
RECORDS: 0
Year Established 2019 Attribution Russia Motivation Financial Modus Operandi (MO) RaaS, supply chain attacks, auctioning stolen data, record-breaking ransom demands Primary Aliases Sodinokibi, GandCrab successor,…
[ VIEW PROFILE ]
Rhysida
ID: RHYSIDA
|
RECORDS: 0
Year Established 2023 Attribution Unknown Motivation Financial Modus Operandi (MO) Double-extortion ransomware, healthcare targeting, VPN exploitation, auctioning victim data Primary Aliases Rhysida Ransomware Group Rhysida…
[ VIEW PROFILE ]
RipperSec
ID: RIPPERSEC
|
RECORDS: 16
Year Established: 2023 Attribution: Global (Malaysia and Singapore-linked leadership reporting) Motivation: Religious and political hacktivism Modus Operandi (MO): Crowdsourced DDoS via MegaMedusa and Zeus Stresser,…
[ VIEW PROFILE ]
Salt Typhoon
ID: SALT-TYPHOON
|
RECORDS: 0
Year Established 2019 Attribution China (MSS) Motivation Espionage, Telecommunications Intelligence Modus Operandi (MO) Telecommunications network infiltration, wiretapping law enforcement intercept systems, metadata collection Primary Aliases…
[ VIEW PROFILE ]
Sandworm
ID: SANDWORM
|
RECORDS: 1
Year Established 2009 Attribution Russia (GRU Unit 74455) Motivation Espionage, Sabotage, Destructive Attacks Modus Operandi (MO) Critical infrastructure attacks, destructive wiper malware, supply chain compromise,…
[ VIEW PROFILE ]
Scattered Spider
ID: SCATTERED-SPIDER
|
RECORDS: 1
Year Established 2022 Attribution Western (USA/UK, Native English Speakers) Motivation Financial Modus Operandi (MO) Social engineering, SIM swapping, MFA fatigue attacks, ransomware deployment, casino and…
[ VIEW PROFILE ]
Server Killers
ID: SERVER-KILLERS
|
RECORDS: 1
Year Established 2023 Attribution Unknown (Southeast Asian Suspected) Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, server disruption, opportunistic targeting Primary Aliases ServerKillers Server Killers…
[ VIEW PROFILE ]
ShinyHunters
ID: SHINYHUNTERS
|
RECORDS: 1
Year Established 2020 Attribution France / Morocco (Members Identified) Motivation Financial, Notoriety Modus Operandi (MO) Large-scale cloud storage data theft, database exfiltration, dark web data…
[ VIEW PROFILE ]
SideWinder
ID: SIDEWINDER
|
RECORDS: 0
Year Established 2012 Attribution India (Suspected) Motivation Espionage Modus Operandi (MO) Mobile device targeting, South Asian military espionage, extremely high attack volume Primary Aliases RattleSnake,…
[ VIEW PROFILE ]
SiegedSec
ID: SIEGEDSEC
|
RECORDS: 0
Year Established 2022 Attribution USA (Suspected) Motivation Hacktivism, LGBTQ+ Advocacy, Anti-Government Modus Operandi (MO) Data leaks, government targeting, anti-conservative political operations Primary Aliases Sieged Sec…
[ VIEW PROFILE ]
Star Blizzard (Seaborgium)
ID: STAR-BLIZZARD-SEABORGIUM
|
RECORDS: 0
Year Established 2017 Attribution Russia (FSB Centre 18) Motivation Espionage, Influence Operations Modus Operandi (MO) Spear-phishing, credential harvesting, NATO and civil society targeting, document theft…
[ VIEW PROFILE ]
Storm-0558
ID: STORM-0558
|
RECORDS: 0
Year Established 2022 Attribution China (MSS Suspected) Motivation Espionage, Diplomatic Intelligence Modus Operandi (MO) Forged authentication tokens, Microsoft cloud account compromise, US government email targeting…
[ VIEW PROFILE ]
TA505 (Cl0p)
ID: TA505-CL0P
|
RECORDS: 0
Year Established 2014 Attribution Russia Motivation Financial Modus Operandi (MO) Mass email campaigns, zero-day exploitation (MOVEit, GoAnywhere), FIN7 ecosystem overlap, mega-breach supply chain attacks Primary…
[ VIEW PROFILE ]
Team Insane PK
ID: TEAM-INSANE-PK
|
RECORDS: 0
Year Established 2022 Attribution Pakistan Motivation Hacktivism, Geopolitical, Anti-India Modus Operandi (MO) Web defacement, DDoS, data leaks targeting Indian government and commercial entities Primary Aliases…
[ VIEW PROFILE ]
TELESHIM and MIXEDKEY
ID: TELESHIM-AND-MIXEDKEY
|
RECORDS: 1
Year Established 2024 Attribution Unknown Motivation Espionage, Persistent Access Modus Operandi (MO) Telegram-based C2, shim-based persistence, combined toolset attacks Primary Aliases TELESHIM, MIXEDKEY TELESHIM and…
[ VIEW PROFILE ]
The FAD Team
ID: THE-FAD-TEAM
|
RECORDS: 1
Year Established 2023 Attribution Unknown (Middle Eastern Suspected) Motivation Hacktivism, Financial Modus Operandi (MO) Web defacement, data leaks, multi-region targeting Primary Aliases FAD Team, FadTeam…
[ VIEW PROFILE ]
The Garuda Eye
ID: THE-GARUDA-EYE
|
RECORDS: 9
Year Established: 2025 Attribution: Global Motivation: Hacktivism, geopolitical signalling Modus Operandi (MO): Layer 7 HTTP floods against government portals, check-host evidence packs, Azure Front Door…
[ VIEW PROFILE ]
TheGentlemen Ransomware
ID: THEGENTLEMEN-RANSOMWARE
|
RECORDS: 3
Year Established 2024 Attribution Unknown Motivation Financial Modus Operandi (MO) Double-extortion ransomware, data leak threats Primary Aliases The Gentlemen, Gentlemen Ransomware Group TheGentlemen Ransomware is…
[ VIEW PROFILE ]
Transparent Tribe
ID: TRANSPARENT-TRIBE
|
RECORDS: 1
Year Established 2013 Attribution Pakistan (ISI Suspected) Motivation Espionage, Military Intelligence Modus Operandi (MO) Crimson RAT, Android malware, honeytrap operations, Indian military and government targeting…
[ VIEW PROFILE ]
Turla
ID: TURLA
|
RECORDS: 0
Year Established 2004 Attribution Russia (FSB) Motivation Espionage, Long-term Intelligence Collection Modus Operandi (MO) Satellite-based C2, hijacking other groups' infrastructure, government and embassy targeting Primary…
[ VIEW PROFILE ]
UNC1151 (Ghostwriter)
ID: UNC1151-GHOSTWRITER
|
RECORDS: 0
Year Established 2017 Attribution Belarus (GRU Suspected Collaboration) Motivation Influence Operations, Espionage Modus Operandi (MO) Hack-and-leak, fabricated government communications, anti-NATO disinformation in Eastern Europe Primary…
[ VIEW PROFILE ]
UNC3886
ID: UNC3886
|
RECORDS: 0
Year Established 2021 Attribution China (State-Sponsored) Motivation Espionage, Persistent Access Modus Operandi (MO) Zero-day exploitation of network appliances, VMware ESXi targeting, firewall firmware attacks Primary…
[ VIEW PROFILE ]
UserSec
ID: USERSEC
|
RECORDS: 0
Year Established 2023 Attribution Russia (Pro-Russian) Motivation Hacktivism, Pro-Russian Geopolitical Modus Operandi (MO) DDoS attacks, coordinating pro-Russian hacktivist alliances, targeting NATO and Ukraine-supporting entities Primary…
[ VIEW PROFILE ]
Volt Typhoon
ID: VOLT-TYPHOON
|
RECORDS: 2
Year Established 2021 Attribution China (PLA/MSS) Motivation Espionage, Pre-positioning for Destructive Attacks Modus Operandi (MO) Living-off-the-land, critical infrastructure pre-positioning, US military and logistics targeting, Taiwan-conflict…
[ VIEW PROFILE ]
Z-BL4CX-H4T.ID
ID: Z-BL4CX-H4T-ID
|
RECORDS: 1
Year Established 2022 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database leaks, Indonesian and international targeting Primary Aliases Z-Blackhat ID, ZBLACKHAT Z-BL4CX-H4T.ID…
[ VIEW PROFILE ]
Z-Pentest Alliance
ID: Z-PENTEST-ALLIANCE
|
RECORDS: 11
Year Established 2023 Attribution Russia (Pro-Russian) Motivation Hacktivism, Sabotage, Pro-Russian Modus Operandi (MO) ICS/SCADA attacks, claiming access to industrial control systems, water and energy infrastructure…
[ VIEW PROFILE ]