Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Threat Actors

APT groups, criminal organizations and other threat actors

Sort by:
Active
TLP:CLEAR

0apt

APT28, Jumpy Pisces, first identified in 2014, 0mid16B

Criminal RU

0APT surfaced on the dark web in late January 2026 as an ostensible Ransomware‑as‑a‑Service (RaaS) platform that marketed free access to a Rust‑based encryptor and claimed a rapid hit rate of over 200 victims. Official ransomware samples have not been verified, yet traffic analyses show typical RaaS infrastructure: a command‑and‑control framework, a web portal for download, and a leak site on Tor offering allegedly stolen data. From the technical evidence available, the malware exhibits classic double‑extortion behavior: it first exfiltrates files via outbound C2 channels (likely over encrypted HTTP/TCP) then encrypts victim data with a custom Rust binary that adds a proprietary extension and deletes shadow copies to hinder recovery. The actor also leverages supply‑chain tactics—compromising third‑party service providers or web applications—and relies on post‑exploitation tools such as Brute Ratel, Cobalt Strike, PowerShell, WMI, and PsExec for lateral movement. While analysts note credible technical depth in the Rust code and infrastructure design, the sheer velocity of alleged “victim” claims coupled with a lack of independently verifiable decryptors strongly suggests many reports are inflated incidents or sandbox self‑attribution attacks. Consequently, 0APT should be treated with caution, particularly by smaller organizations that may inadvertently engage with its RaaS portal.

Ransomware APT Critical Infrastructure Financial gain +8

Confidence

80%
Active
TLP:CLEAR

0day syndicate

tracked as, Jul 6, 2026, Bjorka

Criminal CN

0day Syndicate operates as a ransomware‑as‑a‑service platform that blends traditional phishing vectors with advanced techniques such as AI‑assisted reconnaissance and zero‑click malware delivery. The group distributes malicious URLs, HTA scripts, and ZIP archives to compromise victims’ infrastructure, exploiting known CVEs like CVE‑2026‑60137 and CVE‑2025‑68686 in industrial control systems, VMware Linux kernels, and web applications. Once inside, the actor stages stolen data for exfiltration via a dedicated data‑leak site while simultaneously deploying its flagship Babuk Locker 2.0 / Dispossessor ransomware to encrypt files. The dual approach—data theft + encryption—enables double‑extortion tactics that generate significant financial gains. Command and control is maintained through an IoT‑botnet loader layer using Mirai/Mozi frameworks, coupled with a custom chat‑portal API that allows negotiators to monitor compliance and adjust ransom demands dynamically. This architecture exemplifies the syndicate’s agile operational posture. The group’s portfolio includes auxiliary tools such as Infostealer variants (Dispossessor, win.stealc, win.coinminer), YARA rule generators for stealth detection, and a spectrum of industrial control exploits (PLC, Linux kernel, VMware vulnerabilities). Their global footprint spans the US, EU, Asia, and Brazil, with notable campaigns targeting healthcare, financial services, manufacturing, and critical infrastructure. The most recent incident on 28 May 2026 saw an attack on the Brazilian data‑intelligence firm DXON; the syndicate executed coordinated delivery, encrypted critical files, exfiltrated sensitive data, and issued a public leak threat. This operation showcased their swift execution coupled with psychological pressure tactics, emphasizing the group’s capacity for impactful, high‑profile attacks.

Ransomware Zero-Day Exploitation Financial gain Criminal +20

Confidence

80%

Last seen

May 29, 2026

Active
TLP:CLEAR

0mega

Criminal

0mega, also known in its attack kits as “Omega Lock,” surfaced publicly in May 2022 and has since evolved into a coordinated ransomware outfit that blends technical prowess with classic blackmail. The actors routinely acquire victim credentials via phishing, credential‑dumping (Mimikatz, LaZagne), and exploitation of public‑facing services (T1190). Once inside, they deploy the Omega Lock payload to lock file systems while exfiltrating data through tools such as RClone and then threaten public release unless a ransom is paid. Beyond traditional on‑prem attacks, 0mega targets cloud identity platforms—most notably Microsoft 365 administrator accounts—and modifies Azure or AWS resource provisioning to expand lateral reach without relying solely on compromised local credentials. This adaptability points to a mature threat actor that blends ransomware delivery with sophisticated persistence vectors such as WMI executions, scheduled tasks, and registry tweaks. The group benefits from bulletproof hosting ecosystems (Medialand LLC, ML.Cloud) to distribute malware, host malicious domains for phishing campaigns, and mask command‑and‑control traffic. Defensive measures reveal a pattern of disabling Windows Defender via defoff.bat, clearing event logs, wiping shadow copies, and employing rootkits or obfuscation techniques for stealth. While concrete attribution remains uncertain—some reports link the actors to CIA/JSOC personnel or Russian‐linked infrastructure—independent investigations confirm their financial motivation and high‑value target focus. Overall, 0mega’s operational tempo demonstrates a disciplined blend of phishing, credential dumping, cloud exploitation, and double‑extortion ransomware tactics that make it an evolving threat to multi‑sector entities worldwide.

Ransomware Data Exfiltration DDoS Double-extortion +62

Confidence

80%

Last seen

Jan 25, 2024

Active
TLP:CLEAR

1937CN

Hellsing, Goblin Panda, APT27, APT43

Unknown C

1937CN is a highly capable threat actor linked to Chinese cyber espionage efforts. Core delivery methods rely on macro‑enabled Microsoft Office documents that trigger rundll32 execution of shellcode via a custom loader called ShellFang, enabling initial compromise with limited user interaction. Once inside an environment, the actor leverages widely available public exploits (CVE‑2012‑0158 and CVE‑2017‑11882) to broaden footholds. Persistence is chiefly achieved through GPO manipulation: scheduled tasks are created on domain controllers, and legitimate system tools are hijacked via DLL side‑loading. This approach permits rapid lateral movement without raising obvious alerts in typical monitoring setups. Additionally, advanced adversary techniques such as PowerShell downgrade attacks evade script‑block logging, while RC4‑encrypted payloads obscure data exfiltration. For command and control, the group uses web protocols (HTTPS and HTTP) alongside internal and external proxies to tunnel traffic. Communication is sometimes embedded in seemingly legitimate Office macro traffic or routed through compromised domain names shared with broader Chinese state actors. Remote access trojans—including PlugX/Korplug, NewCore RAT, Sisfader, and MACAMAX—provide persistent footholds, allowing credential harvesting, file manipulation, screen capture, and privileged command execution. Known campaigns include the 2016 disruption of Vietnamese commercial flights via airport control systems, evidence of which indicates that 1937CN’s scope extends beyond espionage into sabotage. Recent operations target Southeast Asian firms across telecom, technology, and media sectors, often utilizing GPO‑based spread to gain domain‑level persistence. The actor’s tactics reveal a layered approach: initial macro delivery, exploitation of known CVEs, lateral movement via GPO/SharpHound, obfuscation through DLL side‑loading and header stripping, and exfiltration using cloud storage or encrypted archives.

APT Government Targeting Hacktivism Cyber espionage +41

Confidence

60%
Active
TLP:CLEAR

313 Team

DarkStorm, 313 Team Hack Team, Islamic Cyber Resistance, Earth Bluecrow

Unknown I

313 Team operates as a front for Iran‑aligned cyber activity, leveraging publicly available tooling from GitHub and other open‑source repositories to orchestrate attacks that are both politically motivated and financially opportunistic. It routinely launches large‑scale volumetric DDoS assaults targeting high‑profile government sites, cloud services, and software distribution platforms, often announcing results on Telegram channels for propaganda value. When defensive suppression fails, the actor escalates to destructive wiper operations—custom malware such as Hatef (Windows) and Hamsa (Linux) are delivered through multi‑stage NSIS or PowerShell chains that later spread via lateral movement using Microsoft Intune’s factory‑reset feature. The group also exploits supply‑chain vulnerabilities by tampering with Trivy Docker images and GitHub releases, embedding persistent backdoors like Dindoor (Denon runtime) and Fakeset (Python) to maintain command‑and‑control over HTTP/HTTPS or Telegram bot channels. Beyond sabotage, 313 Team extends into industrial control system (ICS) domains, manipulating Hikvision surveillance cameras for reconnaissance and attempting PLC exploitation with Seedworm loaders in addition to Intune integration. This diversified toolkit demonstrates a capacity to compromise both public‑facing web components and critical infrastructure while maintaining low detection profiles through legitimate SaaS channels and commercial cloud storage back‑ends. The actor’s operational cadence is tightly aligned with geopolitical developments, deploying attacks within days of regional tensions rising, demanding ransom in cryptocurrencies for campaign cessation, and issuing high‑visibility statements on social feeds to galvanize activist audiences.

APT DDoS Government Targeting Hacktivism +15

Confidence

60%
Active
TLP:CLEAR

4bid

SHADOW-VOID-042, Storm-0978, Tropical Scorpius, APT44

Unknown US

4bid has emerged as one of the most active threat actors in recent years, targeting a broad array of sectors including government, defense, aerospace, energy, healthcare, manufacturing, logistics, education and maritime. In late‑2025 and early‑2026 the group leveraged updated versions of its custom Rust‑based dropper to stage Blackout Locker, deploying it via an obfuscated .dat file written to user AppData and renamed to .exe by cmd.exe. This technique is combined with a suite of backdoors – GoRed (Bulldog), ZeronetKit, BlackReaperRAT, Tuoni, Cobalt Strike, DEEPROOT and others – which are installed either through spear‑phishing attachments or by exploiting zero‑day vulnerabilities such as ProxyShell in Microsoft Exchange and various misconfigurations in Veeam backup, WatchGuard and Confluence. To maintain persistence and facilitate lateral movement the actors use legitimate remote‑access tools including AnyDesk, Panorama9 RMM, ScreenConnect and Splashtop, often bypassing or disabling endpoint protection via BYOVD drivers, signed malware, DLL sideloading, and reverse SSH tunnels. Credential theft is executed through DCSync, LSASS dumping with Mimikatz, and password spraying on VNC/SSH services, while exfiltration frequently occurs to C2 servers over DNS‑over‑HTTPS or encrypted channel protocols such as AES/ChaCha20. 4bid’s recent operations also demonstrate a strategic shift toward monetization: ransomware campaigns such as Blackout Locker and ClearWater now accompany extensive surveillance via backdoors that collect system data, capture screens, harvest cloud credentials, and sabotage industrial control systems. The group has shown an ability to co‑operate with allied threat complexes (e.g., BO Team, Red Likho) by sharing infrastructure and targeting patterns, further amplifying their operational tempo. The actor’s use of both political motives—often framing attacks in a pro-Ukrainian context—and clear financial incentives reflects a hybrid model that enables rapid escalation across borders while capitalizing on the high-value targets within critical sectors.

Ransomware APT Backdoor / C2 DDoS +86

Confidence

55%
Active
TLP:CLEAR

8base

tracked as, double extortion, Fox Kitten, UNC757

Criminal CN

8Base emerged in early 2023 as a commercial ransomware operator that leverages the Phobos code base but customizes its ransom note and delivery chain with the SmokeLoader loader. The loader obfuscates payloads by exploiting .NET profiler tricks, disables Windows Defender through WMIC scripts, and nullifies volume shadow copies via vssadmin commands to accelerate encryption. Once inside a host the group injects credential‑dumping tools such as Mimikatz, LaZagne, WebBrowserPassView, VNCPassView, and ProcDump to harvest credentials, then uses PsExec for lateral movement while escalating privileges through registry UAC hijacks and accessibility utility hijacking (utilman.exe, Magnify.exe). The ransomware also kills database services to avoid file locking before deployment. Prior to encrypting disk volumes, 8Base exfiltrates victim data using RClone or SMTP/IMAP protocols. Each victim’s AES‑256‑CBC payload key is wrapped with an RSA‑1024 public key embedded in the injector; encrypted configurations are stored within PE .cdata/.sdata sections and validated via CRC32 checksums. The gang maintains a TOR‑based Victim Interaction Portal at which compromised files are posted for high recovery rates. This infrastructure enables a structured double‑extortion approach while keeping the ransomware code highly portable across Windows environments.

Ransomware Critical Infrastructure Criminal Double Extortion +10

Confidence

80%

Last seen

Feb 1, 2025

Active
TLP:CLEAR

?

Maverick Panda, PLA Navy, Sykipot, root access

Nation-State CN

APT4 (Maverick Panda/Sykipot) emerged as a PLA Navy intelligence unit that blends traditional espionage with sabotage tactics aimed at critical U.S. infrastructure, particularly civil aviation and defense technology supply chains. Their campaigns typically begin with meticulously crafted spear‑phishing emails or zero‑day exploitation of legitimate software updates, allowing initial access to target environments. Once inside, they deploy a variety of backdoor trojans—most commonly PlugX, Gh0StRAT, UP007, SLServer, and Grabber—to establish stealthy persistence, harvest credentials, and prepare for lateral movement within the network. After establishing footholds, APT4 expands compromised hosts into an extensive botnet. The network is then repurposed for resource hijacking (XMRig mining), ransomware dissemination (e.g., NotPetya variants), or DDoS amplification against state‑controlled or commercial targets. Their supply‑chain infiltration capabilities are demonstrated by the use of legitimate corporate software channels and the targeting of smart card authentication mechanisms used in defense contractor environments. The actor’s toolbox shows a clear progression from data theft missions to destructive campaigns, often coupling espionage with financial incentives and geopolitical messaging. The group’s operational tempo is brisk, shifting from small‑scale intrusions to broad DDoS or cryptomining bursts within weeks while maintaining the option to pivot toward high‑impact ransomware attacks. APT4’s known campaigns—including *Four Element Sword* and a suspected overlapping operation with IXESHE—reveal a pattern of multi‑phase operations that incorporate social engineering, zero‑day delivery mechanisms, post‑exploitation persistence via backdoor trojans, supply‑chain compromise, cryptocurrency mining, and opportunistic ransomware. They have displayed flexibility in both cyber‑defense evasion tactics – such as using legitimate applications to mask malicious activity – and offensive disruption tools.

Ransomware Phishing DDoS Espionage +16

Confidence

70%
Active
TLP:CLEAR

APT-C-01

PoisonVine, APT-Q-20, malicious actors, APT groups

Nation-State CN

APT-C-01 operates under a highly compartmentalized structure that allows it to conduct multi‑phase attacks across numerous industries and geographies. Known aliases such as PoisonVine, APT-Q‑20, and Shell Crew are frequently referenced in threat reports; the actor harnesses both well‑known commercial tools (Poison Ivy, Kanbox RAT) and custom malware families, sometimes leveraging publicly disclosed CVEs (CVE‑2012‑0158, CVE‑2014‑6352, CVE‑2017‑8759). The group’s campaign repertoire includes high‑profile incidents like the Australian Parliament hack and Citrix compromise, underscoring its capability to target sophisticated, high‑value infrastructure. APT-C-01’s threat model centers on stealth, persistence, and exfiltration. Their arsenal spans Windows system modifications including scheduled tasks (T1053.005), service creation (T1543.003), and rootkits (T1014) for long‑term covert presence. Adverse actions are frequently carried out through spearphishing campaigns that deliver malicious attachments or links, often coupled with PowerShell execution (T1059.001), DNS tunneling (T1071.004), and encrypted file carriers to evade detection. The actor’s modular approach—mixing publicly available exploits, custom scripts, and supply‑chain compromises—enables rapid pivoting across sectors while maintaining a low public profile. This results in repeated, often overlapping attacks that aim to harvest strategic or proprietary data for geopolitical advantage.

APT Critical Infrastructure Government Targeting Espionage +8

Confidence

70%
Active
TLP:CLEAR

APT-C-12

Sapphire Mushroom, Blue Mushroom, NuclearCrisis, APT groups

Nation-State CN

APT‑C‑12 is a sophisticated nation‑state actor whose operations date back to 2011. According to 360 TIC, the group has repeatedly infiltrated key units of the Chinese government, military industry, scientific research institutes, and financial services. It focuses specifically on data related to nuclear technology and advanced scientific research, leveraging custom malware development tailored for each engagement. The actor maintains an extensive digital footprint: over 670 distinct malware samples have been observed in the wild, including more than 60 specialized plugins designed for lateral movement across target networks. Its command‑and‑control network consists of upwards of 40 domains and IP addresses that support staging, data exfiltration, and remote control functions. Tactics employed by APT‑C‑12 span a wide spectrum of the ATT&CK framework—ranging from spear‑phishing via attachments or links, exploitation of public‑facing applications, supply‑chain compromises, to stealthy persistence mechanisms like rootkits and web shells. The group heavily utilizes legitimate remote‑access tools and custom backdoors to maintain long‑term access while evading detection. Operational security remains a hallmark: the actor frequently abuses compromised infrastructure (domains, VPS, servers) for acquisition and staging, and uses multi‑hop proxies to obfuscate its traffic. This combination of bespoke malware, expansive infrastructure, and diverse entry techniques allows APT‑C‑12 to conduct high‑value espionage with low visibility to traditional security controls.

Ransomware APT Critical Infrastructure Backdoor / C2 +8

Confidence

60%
Active
TLP:CLEAR

APT-C-13

APT-C-36, Blind Eagle, cybercrime, first appeared around 2018

Apt CN

APT-C‑13 is a sophisticated APT that emerged around 2018 and operates under multiple monikers – including Blind Eagle, Gaza Cybergang Group, and APT‑C‑36. The threat actor has adopted a hybrid arsenal that combines off‑the‑shelf remote access trojans such as MoleRAT and Remcos with bespoke tools, creating a modular campaign architecture. Delivery vectors are heavily anchored in spear‑phishing campaigns featuring malicious documents or .url files disguised as PDFs; once executed, these payloads establish covert channels via nested SSH tunnels and Tor hidden services employing obfs4 to evade DPI. Once inside, the malware maps SMB (445) and RDP (3389) traffic to onion domains, enabling remote data exfiltration through WebDAV or HTTP/HTTPS back‑channels. Persistence is achieved by creating scheduled tasks that masquerade as legitimate software such as Opera GX or Dropbox, while system process creation (T1543) and boot‑time autostart scripts (T1037/T1547) grant endurance. The group exhibits swift tactical evolution, including rapid zero‑day exploitation—most recently CVE‑2024‑43451—and the ability to pivot between offensive capabilities depending on target exposure. APT-C‑13’s operations reflect a focus on espionage against governmental, industrial, and research institutions worldwide, with documented campaigns targeting public and private entities in the Middle East, North Africa, and South America. Its operational tempo reveals short dwell times coupled with precise, data‑driven exfiltration strategies aimed at high‑value strategic information.

APT Phishing Government Targeting Hacktivism +16

Confidence

50%
Leaving Threaticon

This link opens an external site that isn't part of the platform.