🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED
🔍

Flag 313 Team

ID: 313-TEAM | RECORDS: 7
Year Established 2019 Attribution Iran (IRGC-Linked) Motivation Hacktivism, Religious, Anti-Israel Modus Operandi (MO) Web defacement, DDoS, data leaks targeting Israeli and Western entities Primary Aliases…
[ VIEW PROFILE ]

8Base

ID: 8BASE | RECORDS: 0
Year Established 2022 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion ransomware, Phobos ransomware variant, aggressive victim shaming Primary Aliases 8base 8Base…
[ VIEW PROFILE ]

Akatsuki Cyber Team

ID: AKATSUKI-CYBER-TEAM | RECORDS: 1
CLASSIFIED: No public dossier available at this time.
[ VIEW PROFILE ]

Flag Akira Ransomware

ID: AKIRA-RANSOMWARE | RECORDS: 0
Year Established 2023 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion RaaS, Cisco VPN exploitation, retro-aesthetic branding Primary Aliases Akira Akira Ransomware…
[ VIEW PROFILE ]

Flag ALPHV (BlackCat)

ID: ALPHV-BLACKCAT | RECORDS: 0
Year Established 2021 Attribution Russia Motivation Financial Modus Operandi (MO) RaaS, Rust-based cross-platform ransomware, triple extortion, aggressive media relations Primary Aliases BlackCat, ALPHV, Noberus ALPHV,…
[ VIEW PROFILE ]

Flag Andariel

ID: ANDARIEL | RECORDS: 0
Year Established 2015 Attribution North Korea (RGB Bureau 121) Motivation Financial, Espionage, Ransomware Modus Operandi (MO) Healthcare ransomware, defence contractor espionage, cryptocurrency theft Primary Aliases…
[ VIEW PROFILE ]

AnonGhost

ID: ANONGHOST | RECORDS: 0
Year Established 2012 Attribution Unknown (North African / Middle Eastern Suspected) Motivation Hacktivism, Pro-Palestinian, Anti-Israel, Political Modus Operandi (MO) Web defacement, DDoS, mobile app vulnerabilities,…
[ VIEW PROFILE ]

Flag Anonymous Sudan

ID: ANONYMOUS-SUDAN | RECORDS: 0
Year Established 2023 Attribution Sudan / Russia (Pro-Russian Suspected) Motivation Hacktivism, Pro-Russian, Anti-Western, Religious Modus Operandi (MO) High-volume DDoS, cloud platform attacks, critical infrastructure targeting…
[ VIEW PROFILE ]

Flag APT31

ID: APT31 | RECORDS: 0
Year Established 2010 Attribution China (MSS) Motivation Espionage, Political Intelligence Modus Operandi (MO) Spear-phishing, credential theft, journalist and dissident targeting, political campaign interference Primary Aliases…
[ VIEW PROFILE ]

Flag APT32 (OceanLotus)

ID: APT32-OCEANLOTUS | RECORDS: 0
Year Established 2014 Attribution Vietnam (Ministry of Public Security) Motivation Espionage, Corporate Intelligence, Dissident Surveillance Modus Operandi (MO) Spear-phishing, watering hole attacks, custom malware, targeting…
[ VIEW PROFILE ]

Flag APT40

ID: APT40 | RECORDS: 0
Year Established 2013 Attribution China (MSS Hainan State Security Department) Motivation Espionage, Maritime and Naval Intelligence Modus Operandi (MO) Maritime and naval sector targeting, spear-phishing,…
[ VIEW PROFILE ]

Flag APT41

ID: APT41 | RECORDS: 1
Year Established 2012 Attribution China (MSS) Motivation Espionage, Financial Modus Operandi (MO) Dual-track espionage and financial crime, supply chain attacks, zero-day exploitation, video game industry…
[ VIEW PROFILE ]

Flag BABAYO EROR SYSTEM

ID: BABAYO-EROR-SYSTEM | RECORDS: 1
Year Established 2023 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database extraction, regional government targeting Primary Aliases BABAYO ERROR SYSTEM, BES BABAYO…
[ VIEW PROFILE ]

BianLian

ID: BIANLIAN | RECORDS: 0
Year Established 2022 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Data theft extortion pivot (former ransomware), healthcare and critical infrastructure targeting Primary…
[ VIEW PROFILE ]

Flag Black Basta

ID: BLACK-BASTA | RECORDS: 0
Year Established 2022 Attribution Russia (Conti Successor) Motivation Financial Modus Operandi (MO) RaaS, double extortion, social engineering via Microsoft Teams, Conti-linked operators Primary Aliases Black…
[ VIEW PROFILE ]

Flag Black Shadow

ID: BLACK-SHADOW | RECORDS: 0
Year Established 2020 Attribution Iran (IRGC-linked) Motivation Hacktivism, Geopolitical, Disruption Modus Operandi (MO) Data exfiltration, public data leaks, anti-Israel operations, website defacement Primary Aliases BlackShadow…
[ VIEW PROFILE ]

Flag BlueNoroff

ID: BLUENOROFF | RECORDS: 0
Year Established 2016 Attribution North Korea (RGB Bureau 121) Motivation Financial, Cryptocurrency Theft Modus Operandi (MO) SWIFT banking attacks, cryptocurrency exchange targeting, venture capital and…
[ VIEW PROFILE ]

Flag Charming Kitten

ID: CHARMING-KITTEN | RECORDS: 0
Year Established 2014 Attribution Iran (IRGC) Motivation Espionage, Surveillance, Dissident Monitoring Modus Operandi (MO) Fake social media personas, journalist and researcher targeting, phishing via WhatsApp…
[ VIEW PROFILE ]

Flag Cobalt Group

ID: COBALT-GROUP | RECORDS: 0
Year Established 2016 Attribution Russia/Eastern Europe Motivation Financial Modus Operandi (MO) ATM jackpotting, SWIFT banking attacks, spear-phishing financial institutions, Cobalt Strike abuse Primary Aliases GOLD…
[ VIEW PROFILE ]

coinbasecartel

ID: COINBASECARTEL | RECORDS: 1
Year Established 2023 Attribution Unknown Motivation Financial, Cryptocurrency Fraud Modus Operandi (MO) Cryptocurrency exchange targeting, phishing, credential theft, crypto asset theft Primary Aliases Coinbase Cartel…
[ VIEW PROFILE ]

Flag Cozy Bear (APT29)

ID: COZY-BEAR-APT29 | RECORDS: 0
Year Established 2008 Attribution Russia (SVR/FSB) Motivation Espionage, Intelligence Collection Modus Operandi (MO) Spear-phishing, supply chain attacks, cloud exploitation, diplomatic and government targeting Primary Aliases…
[ VIEW PROFILE ]

Kurdistan Cyb3r Drag0nz

ID: CYB3R-DRAG0NZ | RECORDS: 0
Year Established 2022 Attribution Southeast Asia (Suspected) Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, credential dumping, multi-country targeting Primary Aliases Cyber Dragonz, C3D Cyb3r…
[ VIEW PROFILE ]

Flag Cyber Islamic Resistance

ID: CYBER-ISLAMIC-RESISTANCE | RECORDS: 0
Year Established 2023 Attribution Unknown (Middle Eastern Suspected) Motivation Hacktivism, Religious, Pro-Palestinian, Anti-Israel Modus Operandi (MO) DDoS attacks, web defacement, anti-Israel and anti-Western operations Primary…
[ VIEW PROFILE ]

Flag Cyber Team Indonesia

ID: CYBER-TEAM-INDONESIA | RECORDS: 6
Year Established 2021 Attribution Indonesia Motivation Hacktivism, Nationalism, Notoriety Modus Operandi (MO) Web defacement, database extraction, targeting domestic and international e-commerce platforms Primary Aliases CTI,…
[ VIEW PROFILE ]

Flag CyberAv3ngers

ID: CYBERAV3NGERS | RECORDS: 1
Year Established 2020 Attribution Iran (IRGC) Motivation Hacktivism, Geopolitical, Critical Infrastructure Disruption Modus Operandi (MO) ICS/SCADA targeting, water utility attacks, anti-Israel and anti-US operations Primary…
[ VIEW PROFILE ]

CyberLeeks

ID: CYBERLEEKS | RECORDS: 1
Year Established 2026 Attribution Global (Decentralized / Anonymous) Motivation Anti-Corporate Ideology, Clout, Entertainment Industry Data Leaks Modus Operandi (MO) Supply chain exfiltration, social engineering, Telegram…
[ VIEW PROFILE ]

Flag Dark Angels

ID: DARK-ANGELS | RECORDS: 0
Year Established 2022 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Big game hunting, high-value ransomware, quiet negotiation tactics Primary Aliases Dark Angels…
[ VIEW PROFILE ]

Dark Pink

ID: DARK-PINK | RECORDS: 0
Year Established 2021 Attribution Unknown (Southeast Asian Suspected) Motivation Espionage Modus Operandi (MO) Spear-phishing, USB-based propagation, government and military targeting in ASEAN region Primary Aliases…
[ VIEW PROFILE ]

Flag Dark Storm Team

ID: DARK-STORM-TEAM | RECORDS: 3
Year Established 2023 Attribution Pro-Palestinian (International) Motivation Hacktivism, Pro-Palestinian, Anti-Israel, Anti-Western Modus Operandi (MO) DDoS attacks, data leaks, targeting critical infrastructure and media organisations Primary…
[ VIEW PROFILE ]

Flag DarkHotel

ID: DARKHOTEL | RECORDS: 0
Year Established 2007 Attribution South Korea (Suspected) Motivation Espionage, Corporate Intelligence Modus Operandi (MO) Hotel Wi-Fi attacks, spear-phishing senior executives, zero-day exploitation Primary Aliases Dubnium,…
[ VIEW PROFILE ]

Flag DarkSide

ID: DARKSIDE | RECORDS: 0
Year Established 2020 Attribution Russia Motivation Financial Modus Operandi (MO) RaaS, double extortion, critical infrastructure attacks, Colonial Pipeline shutdown Primary Aliases Carbon Spider (partial), BlackMatter…
[ VIEW PROFILE ]

Deadlock Ransomware

ID: DEADLOCK-RANSOMWARE | RECORDS: 1
Year Established 2024 Attribution Unknown Motivation Financial Modus Operandi (MO) Double-extortion ransomware, targeting mid-market enterprises Primary Aliases Deadlock Deadlock Ransomware is an emerging ransomware operation…
[ VIEW PROFILE ]

Flag Dewata Blackhat

ID: DEWATA-BLACKHAT | RECORDS: 4
Year Established 2022 Attribution Indonesia (Bali-origin Suspected) Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping, regional government targeting Primary Aliases DewataBlackhat, Dewata BH…
[ VIEW PROFILE ]

DragonForce Ransomware

ID: DRAGONFORCE-RANSOMWARE | RECORDS: 1
Year Established 2023 Attribution Malaysia (Suspected) Motivation Financial, Hacktivism (Origins) Modus Operandi (MO) RaaS, LockBit/Conti-based ransomware, pivot from hacktivism to criminal ransomware operation Primary Aliases…
[ VIEW PROFILE ]

Flag Earth Krahang

ID: EARTH-KRAHANG | RECORDS: 0
Year Established 2022 Attribution China (MSS Affiliated) Motivation Espionage, Government Intelligence Collection Modus Operandi (MO) Compromised government infrastructure for lateral attacks, spear-phishing, VPN exploitation, Southeast…
[ VIEW PROFILE ]

Flag Equation Group

ID: EQUATION-GROUP | RECORDS: 0
Year Established 2001 Attribution USA (NSA/TAO) Motivation Espionage, Critical Infrastructure Access, Global Signals Intelligence Modus Operandi (MO) HDD firmware implants, air-gap bridging, nation-state-level zero-days, PRISM-adjacent…
[ VIEW PROFILE ]

Flag Fancy Bear (APT28)

ID: FANCY-BEAR-APT28 | RECORDS: 0
Year Established 2004 Attribution Russia (GRU Unit 26165 & 74455) Motivation Espionage, Influence Operations, Election Interference Modus Operandi (MO) Credential phishing, X-Agent/Sofacy malware, election infrastructure…
[ VIEW PROFILE ]

Kurdistan FEMBOYSec

ID: FEMBOYSEC | RECORDS: 4
Year Established 2023 Attribution Unknown (Western, English-Speaking Suspected) Motivation Hacktivism, Notoriety, LGBTQ+ Adjacent Modus Operandi (MO) Web defacement, data leaks, edgelord-style provocative branding Primary Aliases…
[ VIEW PROFILE ]

Flag FIN7

ID: FIN7 | RECORDS: 0
Year Established 2015 Attribution Russia/Ukraine Motivation Financial Modus Operandi (MO) Point-of-sale malware, spear-phishing restaurant/hospitality chains, CARBANAK malware, ransomware pivot Primary Aliases Carbanak Group, Navigator Group,…
[ VIEW PROFILE ]

Flag Flax Typhoon

ID: FLAX-TYPHOON | RECORDS: 0
Year Established 2021 Attribution China (MSS) Motivation Espionage, Persistent Access Modus Operandi (MO) Living-off-the-land techniques, VPN exploitation, Taiwan-focused espionage Primary Aliases Ethereal Panda, RedJuliett Flax…
[ VIEW PROFILE ]

Flag Gamaredon

ID: GAMAREDON | RECORDS: 0
Year Established 2013 Attribution Russia (FSB) Motivation Espionage, Sabotage (Ukraine-focused) Modus Operandi (MO) Massive-scale Ukraine targeting, phishing, USB worms, template injection, near-daily attack operations Primary…
[ VIEW PROFILE ]

Flag GANOSEC Team

ID: GANOSEC-TEAM | RECORDS: 0
Year Established 2022 Attribution Indonesia Motivation Hacktivism, Nationalism, Pro-Palestinian Modus Operandi (MO) Web defacement, DDoS, database dumping, coordinated campaigns Primary Aliases Ganosec, GANO Security Team…
[ VIEW PROFILE ]

Flag Garuda Kernel Error System

ID: GARUDA-KERNEL-ERROR-SYSTEM | RECORDS: 2
Year Established 2024 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database exploitation Primary Aliases GKES, Garuda Kernel Garuda Kernel Error System (GKES)…
[ VIEW PROFILE ]

GhostSec

ID: GHOSTSEC | RECORDS: 0
Year Established 2015 Attribution Unknown (International) Motivation Hacktivism, Anti-ISIS, Later Pro-Palestinian, Financial (Ransomware pivot) Modus Operandi (MO) Counter-terrorism operations, website takedowns, data leaks, ransomware deployment…
[ VIEW PROFILE ]

Flag Gorgon Group

ID: GORGON-GROUP | RECORDS: 0
Year Established 2018 Attribution Pakistan Motivation Espionage, Financial Crime Modus Operandi (MO) Dual-track espionage and cybercrime, RevengeRAT delivery, targeting Western governments and financial institutions Primary…
[ VIEW PROFILE ]

GUNRA

ID: GUNRA | RECORDS: 1
Year Established 2024 Attribution Unknown Motivation Financial Modus Operandi (MO) Double-extortion ransomware, targeting corporate networks, data leak threats Primary Aliases GUNRA Ransomware GUNRA is an…
[ VIEW PROFILE ]

Flag Hafnium

ID: HAFNIUM | RECORDS: 0
Year Established 2021 Attribution China (MSS) Motivation Espionage Modus Operandi (MO) Microsoft Exchange zero-day exploitation (ProxyLogon), web shell deployment, US defence contractor and NGO targeting…
[ VIEW PROFILE ]

Flag HANDALA

ID: HANDALA | RECORDS: 4
Year Established 2023 Attribution Iran (Suspected) Motivation Hacktivism, Pro-Palestinian, Anti-Israel Modus Operandi (MO) Destructive wiper attacks, data leaks, psychological operations against Israeli targets Primary Aliases…
[ VIEW PROFILE ]

Flag HMEI7

ID: HMEI7 | RECORDS: 0
Year Established 2008 Attribution Iran (Suspected) Motivation Hacktivism, Pro-Palestinian, Anti-Israel, Religious Modus Operandi (MO) Mass web defacement campaigns, one of the longest-running defacement groups globally…
[ VIEW PROFILE ]

Flag Hunters International

ID: HUNTERS-INTERNATIONAL | RECORDS: 0
Year Established 2023 Attribution Unknown Motivation Financial Modus Operandi (MO) RaaS, data theft extortion, suspected Hive ransomware successor Primary Aliases Hunters Hunters International is a…
[ VIEW PROFILE ]

INC Ransomware

ID: INC-RANSOMWARE | RECORDS: 1
Year Established 2023 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion ransomware, healthcare and education targeting, Citrix and VPN exploitation Primary Aliases…
[ VIEW PROFILE ]

Flag Indian Cyber Force

ID: INDIAN-CYBER-FORCE | RECORDS: 0
Year Established 2022 Attribution India Motivation Hacktivism, Nationalism, Anti-Pakistan, Anti-China Modus Operandi (MO) Web defacement, DDoS, database leaks targeting Pakistani and Chinese entities Primary Aliases…
[ VIEW PROFILE ]

Flag INDOHAXSEC

ID: INDOHAXSEC | RECORDS: 1
Year Established 2023 Attribution Indonesia Motivation Hacktivism, Geopolitical Modus Operandi (MO) DDoS attacks, web defacement, data leaks, pro-Palestinian operations Primary Aliases IndoHaxSec, Indonesian Haxsec INDOHAXSEC…
[ VIEW PROFILE ]

Infrastructure Destruction Squad

ID: INFRASTRUCTURE-DESTRUCTION-SQUAD | RECORDS: 1
Year Established 2024 Attribution Unknown (Pro-Russian Suspected) Motivation Hacktivism, Sabotage, Geopolitical Modus Operandi (MO) ICS/SCADA targeting, critical infrastructure disruption, destructive attacks Primary Aliases IDS, Infra…
[ VIEW PROFILE ]

JADEPUFFER

ID: JADEPUFFER | RECORDS: 1
Year Established 2025 Attribution Unknown (AI-Assisted Operations) Motivation Financial, Espionage Modus Operandi (MO) AI-augmented ransomware development, autonomous attack chain execution, adaptive evasion Primary Aliases JADE…
[ VIEW PROFILE ]

Flag JundAlNabi

ID: JUNDALNABI | RECORDS: 3
Year Established 2024 Attribution Pakistan Motivation Hacktivism, Religious, Pro-Palestinian Modus Operandi (MO) DDoS, web defacement, data exfiltration Primary Aliases Jund Al Nabi, JAN JundAlNabi is…
[ VIEW PROFILE ]

K3LLLEAKERS

ID: K3LLLEAKERS | RECORDS: 1
K3LLLEAKERS is a hacktivist and data breach entity known for leaking government database archives and targeting public sector infrastructure in Southeast Asia.
[ VIEW PROFILE ]

Karakurt

ID: KARAKURT | RECORDS: 0
Year Established 2021 Attribution Russia (Conti Group Affiliated) Motivation Financial Modus Operandi (MO) Data theft extortion without encryption, Conti/Diavol-linked infrastructure Primary Aliases Karakurt Team, Karakurt…
[ VIEW PROFILE ]

Flag KARAWANG ERROR SYSTEM

ID: KARAWANG-ERROR-SYSTEM-2 | RECORDS: 1
Year Established 2024 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping Primary Aliases KES, Karawang Error KARAWANG ERROR SYSTEM (KES) is…
[ VIEW PROFILE ]

Flag Keymous

ID: KEYMOUS | RECORDS: 0
Year Established 2022 Attribution Unknown (North African Suspected) Motivation Hacktivism, Financial Modus Operandi (MO) Database leaks, credential theft, dark web data sales Primary Aliases Keymous+,…
[ VIEW PROFILE ]

Flag Killnet

ID: KILLNET | RECORDS: 0
Year Established 2022 Attribution Russia (Pro-Russian) Motivation Hacktivism, Pro-Russian, Anti-NATO Modus Operandi (MO) DDoS attacks, coordinating pro-Russian hacktivist alliances, propaganda operations Primary Aliases KillNet, Kill…
[ VIEW PROFILE ]

Flag Kimsuky (APT43)

ID: KIMSUKY-APT43 | RECORDS: 0
Year Established 2012 Attribution North Korea (RGB) Motivation Espionage, Policy Intelligence, Nuclear Monitoring Modus Operandi (MO) Spear-phishing, fake think tank personas, Korean peninsula policy researcher…
[ VIEW PROFILE ]

Flag Lapsus$

ID: LAPSUS | RECORDS: 0
Year Established 2021 Attribution UK / Brazil / International (Teenagers) Motivation Notoriety, Financial Modus Operandi (MO) Social engineering, SIM swapping, insider recruitment, targeting major tech…
[ VIEW PROFILE ]

Flag Laundry Bear APT

ID: LAUNDRY-BEAR-APT | RECORDS: 0
Year Established 2024 Attribution Russia (Suspected) Motivation Espionage, Information Operations Modus Operandi (MO) Supply chain compromise, credential theft, intelligence gathering Primary Aliases Laundry Bear, UNC5812…
[ VIEW PROFILE ]

Flag Lazarus Group

ID: LAZARUS-GROUP | RECORDS: 0
Year Established 2009 Attribution North Korea (RGB Bureau 121) Motivation Financial, Espionage, Sabotage Modus Operandi (MO) Cryptocurrency heists, SWIFT banking attacks, supply chain compromise, espionage,…
[ VIEW PROFILE ]

LockBit

ID: LOCKBIT | RECORDS: 0
Year Established 2019 Attribution Russia (Suspected) Motivation Financial Modus Operandi (MO) RaaS, most prolific ransomware of its era, aggressive affiliate model, automated propagation Primary Aliases…
[ VIEW PROFILE ]

Flag LulzSec Indonesia

ID: LULZSEC-INDONESIA | RECORDS: 0
Year Established 2020 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping, adoption of LulzSec branding Primary Aliases LulzSecIndo LulzSec Indonesia is…
[ VIEW PROFILE ]

Flag LunarisSec

ID: LUNARISSEC | RECORDS: 1
Year Established 2023 Attribution Unknown Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping, multi-country targeting Primary Aliases Lunaris Security, Lunaris LunarisSec is a…
[ VIEW PROFILE ]

Magecart

ID: MAGECART | RECORDS: 0
Year Established 2015 Attribution Multiple Groups (International) Motivation Financial Modus Operandi (MO) Web skimming, JavaScript injection into e-commerce checkout pages, payment card theft at scale…
[ VIEW PROFILE ]

Flag Medusa Ransomware

ID: MEDUSA-RANSOMWARE | RECORDS: 0
Year Established 2021 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion RaaS, education and healthcare targeting, public countdown timers Primary Aliases Medusa,…
[ VIEW PROFILE ]

Flag Midnight Blizzard (Nobelium)

ID: MIDNIGHT-BLIZZARD-NOBELIUM | RECORDS: 0
Year Established 2018 Attribution Russia (SVR) Motivation Espionage Modus Operandi (MO) Supply chain attacks, OAuth abuse, cloud environment targeting, diplomatic and government espionage Primary Aliases…
[ VIEW PROFILE ]

Flag Mint Sandstorm (APT35)

ID: MINT-SANDSTORM-APT35 | RECORDS: 0
Year Established 2014 Attribution Iran (IRGC) Motivation Espionage, Influence Operations, Journalist and Researcher Targeting Modus Operandi (MO) Spear-phishing, fake conference invitations, credential harvesting, targeting journalists…
[ VIEW PROFILE ]

Flag MuddyWater

ID: MUDDYWATER | RECORDS: 0
Year Established 2017 Attribution Iran (MOIS) Motivation Espionage, Influence Operations Modus Operandi (MO) Spear-phishing, PowerShell-based malware, Middle East and European government targeting Primary Aliases Static…
[ VIEW PROFILE ]

Flag Mustang Panda

ID: MUSTANG-PANDA | RECORDS: 0
Year Established 2012 Attribution China (MSS) Motivation Espionage, Political Intelligence Modus Operandi (MO) Spear-phishing with PlugX malware, USB propagation, targeting Southeast Asian governments and NGOs…
[ VIEW PROFILE ]

Kurdistan N1ghtSp1d3rz

ID: N1GHTSP1D3RZ | RECORDS: 1
Year Established 2023 Attribution Unknown (Southeast Asian Suspected) Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database leaks, multi-sector targeting Primary Aliases Night Spiderz, NightSpiders…
[ VIEW PROFILE ]

Flag NoName057(16)

ID: NONAME057 | RECORDS: 30
Year Established 2022 Attribution Russia (Pro-Russian) Motivation Hacktivism, Pro-Russian, Anti-NATO Modus Operandi (MO) Coordinated DDoS via volunteer botnet (DDoSia tool), targeting NATO and Ukraine-supporting nations…
[ VIEW PROFILE ]

Flag Nullsec Nigeria

ID: NULLSEC-NIGERIA | RECORDS: 1
Year Established 2024 Attribution Nigeria Motivation Financial, Hacktivism Modus Operandi (MO) Data extortion, fake breach claims, social media pressure tactics Primary Aliases NullSec NG, NullSec…
[ VIEW PROFILE ]

Flag OilRig

ID: OILRIG | RECORDS: 1
Year Established 2014 Attribution Iran (MOIS/IRGC) Motivation Espionage, Persistent Access Modus Operandi (MO) Spear-phishing, custom malware (POWRUNER, BONDUPDATER), Middle East government and energy sector targeting…
[ VIEW PROFILE ]

Flag Panoc Team

ID: PANOC-TEAM | RECORDS: 0
Year Established 2023 Attribution Unknown Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database dumping, low-sophistication opportunistic attacks Primary Aliases Panic Team Panoc Team is…
[ VIEW PROFILE ]

Flag Patchwork APT

ID: PATCHWORK-APT | RECORDS: 0
Year Established 2015 Attribution India (Suspected) Motivation Espionage Modus Operandi (MO) Spear-phishing, BADNEWS malware, targeting Pakistan, China, and Southeast Asian governments Primary Aliases Dropping Elephant,…
[ VIEW PROFILE ]

Flag People's Cyber Army

ID: PEOPLES-CYBER-ARMY | RECORDS: 0
Year Established 2022 Attribution Russia (Pro-Russian) Motivation Hacktivism, Pro-Russian, Anti-Ukraine, Anti-NATO Modus Operandi (MO) DDoS attacks, coordinating volunteer cyber operations, targeting NATO and Ukraine-supporting entities…
[ VIEW PROFILE ]

Flag Pioneer Kitten

ID: PIONEER-KITTEN | RECORDS: 0
Year Established 2017 Attribution Iran (IRGC Contracted) Motivation Espionage, Financial (Ransomware Collaboration) Modus Operandi (MO) VPN and firewall zero-day exploitation, selling network access, ransomware partnership…
[ VIEW PROFILE ]

Flag Play Ransomware

ID: PLAY-RANSOMWARE | RECORDS: 0
Year Established 2022 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) Double-extortion ransomware, Exchange server exploitation, no negotiation policy Primary Aliases PlayCrypt, Play…
[ VIEW PROFILE ]

Flag Predatory Sparrow

ID: PREDATORY-SPARROW | RECORDS: 0
Year Established 2021 Attribution Israel (Suspected) Motivation Sabotage, Geopolitical, Counter-Iran Modus Operandi (MO) Destructive ICS/SCADA attacks against Iranian infrastructure, wiper malware, psychological operations Primary Aliases…
[ VIEW PROFILE ]

Flag Qilin

ID: QILIN | RECORDS: 0
Year Established 2023 Attribution China (Suspected) Motivation Financial Modus Operandi (MO) Ransomware-as-a-Service (RaaS), double-extortion, healthcare and critical infrastructure targeting Primary Aliases Agenda Ransomware, Qilin Ransomware…
[ VIEW PROFILE ]

RansomHouse

ID: RANSOMHOUSE | RECORDS: 1
Year Established 2021 Attribution Unknown Motivation Financial Modus Operandi (MO) Data theft extortion without ransomware, marketplace model for stolen data, corporate targeting Primary Aliases Ransomhouse,…
[ VIEW PROFILE ]

RansomHub

ID: RANSOMHUB | RECORDS: 0
Year Established 2024 Attribution Unknown (Eastern European Suspected) Motivation Financial Modus Operandi (MO) RaaS, aggressive affiliate recruitment, targeting critical infrastructure Primary Aliases Ransomhub RansomHub is…
[ VIEW PROFILE ]

Flag Red Apollo (APT10)

ID: RED-APOLLO-APT10 | RECORDS: 0
Year Established 2009 Attribution China (MSS) Motivation Espionage, Intellectual Property Theft Modus Operandi (MO) Managed service provider (MSP) compromise, supply chain attacks, global IP theft…
[ VIEW PROFILE ]

Flag REvil (Sodinokibi)

ID: REVIL-SODINOKIBI | RECORDS: 0
Year Established 2019 Attribution Russia Motivation Financial Modus Operandi (MO) RaaS, supply chain attacks, auctioning stolen data, record-breaking ransom demands Primary Aliases Sodinokibi, GandCrab successor,…
[ VIEW PROFILE ]

Flag Rhysida

ID: RHYSIDA | RECORDS: 0
Year Established 2023 Attribution Unknown Motivation Financial Modus Operandi (MO) Double-extortion ransomware, healthcare targeting, VPN exploitation, auctioning victim data Primary Aliases Rhysida Ransomware Group Rhysida…
[ VIEW PROFILE ]

RipperSec

ID: RIPPERSEC | RECORDS: 16
Year Established: 2023 Attribution: Global (Malaysia and Singapore-linked leadership reporting) Motivation: Religious and political hacktivism Modus Operandi (MO): Crowdsourced DDoS via MegaMedusa and Zeus Stresser,…
[ VIEW PROFILE ]

Flag Salt Typhoon

ID: SALT-TYPHOON | RECORDS: 0
Year Established 2019 Attribution China (MSS) Motivation Espionage, Telecommunications Intelligence Modus Operandi (MO) Telecommunications network infiltration, wiretapping law enforcement intercept systems, metadata collection Primary Aliases…
[ VIEW PROFILE ]

Flag Sandworm

ID: SANDWORM | RECORDS: 1
Year Established 2009 Attribution Russia (GRU Unit 74455) Motivation Espionage, Sabotage, Destructive Attacks Modus Operandi (MO) Critical infrastructure attacks, destructive wiper malware, supply chain compromise,…
[ VIEW PROFILE ]

Scattered Spider

ID: SCATTERED-SPIDER | RECORDS: 1
Year Established 2022 Attribution Western (USA/UK, Native English Speakers) Motivation Financial Modus Operandi (MO) Social engineering, SIM swapping, MFA fatigue attacks, ransomware deployment, casino and…
[ VIEW PROFILE ]

Flag Server Killers

ID: SERVER-KILLERS | RECORDS: 1
Year Established 2023 Attribution Unknown (Southeast Asian Suspected) Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, server disruption, opportunistic targeting Primary Aliases ServerKillers Server Killers…
[ VIEW PROFILE ]

ShinyHunters

ID: SHINYHUNTERS | RECORDS: 1
Year Established 2020 Attribution France / Morocco (Members Identified) Motivation Financial, Notoriety Modus Operandi (MO) Large-scale cloud storage data theft, database exfiltration, dark web data…
[ VIEW PROFILE ]

Flag SideWinder

ID: SIDEWINDER | RECORDS: 0
Year Established 2012 Attribution India (Suspected) Motivation Espionage Modus Operandi (MO) Mobile device targeting, South Asian military espionage, extremely high attack volume Primary Aliases RattleSnake,…
[ VIEW PROFILE ]

Flag SiegedSec

ID: SIEGEDSEC | RECORDS: 0
Year Established 2022 Attribution USA (Suspected) Motivation Hacktivism, LGBTQ+ Advocacy, Anti-Government Modus Operandi (MO) Data leaks, government targeting, anti-conservative political operations Primary Aliases Sieged Sec…
[ VIEW PROFILE ]

Flag Star Blizzard (Seaborgium)

ID: STAR-BLIZZARD-SEABORGIUM | RECORDS: 0
Year Established 2017 Attribution Russia (FSB Centre 18) Motivation Espionage, Influence Operations Modus Operandi (MO) Spear-phishing, credential harvesting, NATO and civil society targeting, document theft…
[ VIEW PROFILE ]

Flag Storm-0558

ID: STORM-0558 | RECORDS: 0
Year Established 2022 Attribution China (MSS Suspected) Motivation Espionage, Diplomatic Intelligence Modus Operandi (MO) Forged authentication tokens, Microsoft cloud account compromise, US government email targeting…
[ VIEW PROFILE ]

Flag TA505 (Cl0p)

ID: TA505-CL0P | RECORDS: 0
Year Established 2014 Attribution Russia Motivation Financial Modus Operandi (MO) Mass email campaigns, zero-day exploitation (MOVEit, GoAnywhere), FIN7 ecosystem overlap, mega-breach supply chain attacks Primary…
[ VIEW PROFILE ]

Flag Team Insane PK

ID: TEAM-INSANE-PK | RECORDS: 0
Year Established 2022 Attribution Pakistan Motivation Hacktivism, Geopolitical, Anti-India Modus Operandi (MO) Web defacement, DDoS, data leaks targeting Indian government and commercial entities Primary Aliases…
[ VIEW PROFILE ]

TELESHIM and MIXEDKEY

ID: TELESHIM-AND-MIXEDKEY | RECORDS: 1
Year Established 2024 Attribution Unknown Motivation Espionage, Persistent Access Modus Operandi (MO) Telegram-based C2, shim-based persistence, combined toolset attacks Primary Aliases TELESHIM, MIXEDKEY TELESHIM and…
[ VIEW PROFILE ]

The FAD Team

ID: THE-FAD-TEAM | RECORDS: 1
Year Established 2023 Attribution Unknown (Middle Eastern Suspected) Motivation Hacktivism, Financial Modus Operandi (MO) Web defacement, data leaks, multi-region targeting Primary Aliases FAD Team, FadTeam…
[ VIEW PROFILE ]

The Garuda Eye

ID: THE-GARUDA-EYE | RECORDS: 9
Year Established: 2025 Attribution: Global Motivation: Hacktivism, geopolitical signalling Modus Operandi (MO): Layer 7 HTTP floods against government portals, check-host evidence packs, Azure Front Door…
[ VIEW PROFILE ]

Flag TheGentlemen Ransomware

ID: THEGENTLEMEN-RANSOMWARE | RECORDS: 3
Year Established 2024 Attribution Unknown Motivation Financial Modus Operandi (MO) Double-extortion ransomware, data leak threats Primary Aliases The Gentlemen, Gentlemen Ransomware Group TheGentlemen Ransomware is…
[ VIEW PROFILE ]

Flag Transparent Tribe

ID: TRANSPARENT-TRIBE | RECORDS: 1
Year Established 2013 Attribution Pakistan (ISI Suspected) Motivation Espionage, Military Intelligence Modus Operandi (MO) Crimson RAT, Android malware, honeytrap operations, Indian military and government targeting…
[ VIEW PROFILE ]

Flag Turla

ID: TURLA | RECORDS: 0
Year Established 2004 Attribution Russia (FSB) Motivation Espionage, Long-term Intelligence Collection Modus Operandi (MO) Satellite-based C2, hijacking other groups' infrastructure, government and embassy targeting Primary…
[ VIEW PROFILE ]

Flag UNC1151 (Ghostwriter)

ID: UNC1151-GHOSTWRITER | RECORDS: 0
Year Established 2017 Attribution Belarus (GRU Suspected Collaboration) Motivation Influence Operations, Espionage Modus Operandi (MO) Hack-and-leak, fabricated government communications, anti-NATO disinformation in Eastern Europe Primary…
[ VIEW PROFILE ]

Flag UNC3886

ID: UNC3886 | RECORDS: 0
Year Established 2021 Attribution China (State-Sponsored) Motivation Espionage, Persistent Access Modus Operandi (MO) Zero-day exploitation of network appliances, VMware ESXi targeting, firewall firmware attacks Primary…
[ VIEW PROFILE ]

Flag UserSec

ID: USERSEC | RECORDS: 0
Year Established 2023 Attribution Russia (Pro-Russian) Motivation Hacktivism, Pro-Russian Geopolitical Modus Operandi (MO) DDoS attacks, coordinating pro-Russian hacktivist alliances, targeting NATO and Ukraine-supporting entities Primary…
[ VIEW PROFILE ]

Flag Volt Typhoon

ID: VOLT-TYPHOON | RECORDS: 2
Year Established 2021 Attribution China (PLA/MSS) Motivation Espionage, Pre-positioning for Destructive Attacks Modus Operandi (MO) Living-off-the-land, critical infrastructure pre-positioning, US military and logistics targeting, Taiwan-conflict…
[ VIEW PROFILE ]

Flag Z-BL4CX-H4T.ID

ID: Z-BL4CX-H4T-ID | RECORDS: 1
Year Established 2022 Attribution Indonesia Motivation Hacktivism, Notoriety Modus Operandi (MO) Web defacement, database leaks, Indonesian and international targeting Primary Aliases Z-Blackhat ID, ZBLACKHAT Z-BL4CX-H4T.ID…
[ VIEW PROFILE ]

Flag Z-Pentest Alliance

ID: Z-PENTEST-ALLIANCE | RECORDS: 11
Year Established 2023 Attribution Russia (Pro-Russian) Motivation Hacktivism, Sabotage, Pro-Russian Modus Operandi (MO) ICS/SCADA attacks, claiming access to industrial control systems, water and energy infrastructure…
[ VIEW PROFILE ]