Leading threat actors
ranked by ATT&CK depth + activityStorm-1567AkiraPUNK SPIDERStorm-1567 is the threat actor behind the Ransomware-as-a-Service Akira. They attacked Swedish organizations in March 2023. This ransomware utilizes the ChaCha encryption algorithm, PowerShell, and Windows Management Instrumentation (WMI). Microsoft's Defender for Endpoint successfully blocked a large-scale hacking campaign carried out by Storm-1567, highlighting the effectiveness of their security solution.62 victims · active 18d · G1024playInitially observed in June 2022, the Play ransomware (a.k.a PlayCrypt) operates through double extortion, targeting numerous organizations in Latin America. Its Initial Access method is quite similar to other ransomwares, involving attacks such as Phishing, Exposed Services to the Internet, and Valid Account compromises.<br> <br> On April 19, 2023, the security company Symantec published two new tools developed by the Play group. These tools allow the malicious actor to enumerate and exfiltrate data from the internal network. The post mentions the following: 'Play threat actors use the .NET infostealer to enumerate software and services via WMI, WinRM, Remote Registry, and Remote Service. The malware checks for the existence of security and backup software, as well as remote administration tools and other programs, saving the information in .CSV files that are compressed into a .ZIP file for later manual exfiltration by threat actors.'Source: https://github.com/crocodyli/ThreatActors-TTPscrime38 victims · active 14d · G1040ShinyHuntersUNC6240Bling LibraShinyHunters is a cybercriminal group of unknown origin that is motivated by financial gain. The group is known for its sophisticated attacks against a wide range of targets, including businesses, organizations, and government agencies. ShinyHunters typically uses phishing attacks and exploit kits to gain access to victim networks, where they deploy malware to steal sensitive data, such as names, addresses, phone numbers, Social Security numbers, and credit card information.35 victims · active 18d · G1057LAPSUSLAPSUS$DEV-0537An actor group conducting large-scale social engineering and extortion campaign against multiple organizations with some seeing evidence of destructive elements.3 victims · active 2mo · G1004APT41G0096TA415APT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially outside of state control.nation-stateChinaG0044MUSTANG PANDABRONZE PRESIDENTHoneyMyteThis threat actor targets nongovernmental organizations using Mongolian-themed lures for espionage purposes.
In April 2017, CrowdStrike Falcon Intelligence observed a previously unattributed actor group with a Chinese nexus targeting a U.S.-based think tank. Further analysis revealed a wider campaign with unique tactics, techniques, and procedures (TTPs). This adversary targets non-governmental organizations (NGOs) in general, but uses Mongolian language decoys and themes, suggesting this actor has a specific focus on gathering intelligence on Mongolia. These campaigns involve the use of shared malware like Poison Ivy or PlugX.
Recently, Falcon Intelligence observed new activity from MUSTANG PANDA, using a unique infection chain to target likely Mongolia-based victims. This newly observed activity uses a series of redirections and fileless, malicious implementations of legitimate tools to gain access to the targeted systems. Additionally, MUSTANG PANDA actors reused previously-observed legitimate domains to host files.nation-stateChinaG1014ENERGETIC BEARBERSERK BEARALLANITEA Russian group that collects intelligence on the energy industry.nation-stateRussiaG0035KimsukyVelvet ChollimaBlack BansheeThis threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.nation-stateNorth KoreaG0094APT29Group 100COZY BEARA 2015 report by F-Secure describe APT29 as: 'The Dukes are a well-resourced, highly dedicated and organized cyberespionage group that we believe has been working for the Russian Federation since at least 2008 to collect intelligence in support of foreign and security policy decision-making. The Dukes show unusual confidence in their ability to continue successfully compromising their targets, as well as in their ability to operate with impunity. The Dukes primarily target Western governments and related organizations, such as government ministries and agencies, political think tanks, and governmental subcontractors. Their targets have also included the governments of members of the Commonwealth of Independent States;Asian, African, and Middle Eastern governments;organizations associated with Chechen extremism;and Russian speakers engaged in the illicit trade of controlled substances and drugs. The Dukes are known to employ a vast arsenal of malware toolsets, which we identify as MiniDuke, CosmicDuke, OnionDuke, CozyDuke, CloudDuke, SeaDuke, HammerDuke, PinchDuke, and GeminiDuke. In recent years, the Dukes have engaged in apparently biannual large - scale spear - phishing campaigns against hundreds or even thousands of recipients associated with governmental institutions and affiliated organizations. These campaigns utilize a smash - and - grab approach involving a fast but noisy breakin followed by the rapid collection and exfiltration of as much data as possible.If the compromised target is discovered to be of value, the Dukes will quickly switch the toolset used and move to using stealthier tactics focused on persistent compromise and long - term intelligence gathering. This threat actor targets government ministries and agencies in the West, Central Asia, East Africa, and the Middle East; Chechen extremist groups; Russian organized crime; and think tanks. It is suspected to be behind the 2015 compromise of unclassified networks at the White House, Department of State, Pentagon, and the Joint Chiefs of Staff. The threat actor includes all of the Dukes tool sets, including MiniDuke, CosmicDuke, OnionDuke, CozyDuke, SeaDuke, CloudDuke (aka MiniDionis), and HammerDuke (aka Hammertoss). 'nation-stateRussiaG0016Earth LuscaCHROMIUMControlXEarth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication companies, religious organizations, and other civil society groups. Earth Lusca's tools closely resemble those used by Winnti Umbrella, but the group appears to operate separately from Winnti. Earth Lusca has also been observed targeting cryptocurrency payment platforms and cryptocurrency exchanges in what are likely financially motivated attacks.ChinaG1006Lazarus GroupOperation DarkSeoulDark SeoulSince 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltration of data while others have been disruptive in nature. Commercial reporting has referred to this activity as Lazarus Group and Guardians of Peace. Tools and capabilities used by HIDDEN COBRA actors include DDoS botnets, keyloggers, remote access tools (RATs), and wiper malware. Variants of malware and tools used by HIDDEN COBRA actors include Destover, Duuzer, and Hangman.nation-stateNorth KoreaG1036MoleratsGaza Hackers TeamGaza cybergangIn October 2012, malware attacks against Israeli government targets grabbed media attention as officials temporarily cut off Internet access for its entire police force and banned the use of USB memory sticks. Security researchers subsequently linked these attacks to a broader, yearlong campaign that targeted not just Israelis but Palestinians as well. and as discovered later, even the U.S. and UK governments. Further research revealed a connection between these attacks and members of the so-called “Gaza Hackers Team.” We refer to this campaign as “Molerats.”nation-statePalestineG0021APT27GreedyTaotieTG-3390A China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.ChinaG0027APT28Pawn StormFANCY BEARThe Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely operating since 2007, the group is known to target government, military, and security organizations. It has been characterized as an advanced persistent threat.nation-stateRussiaG0007CleaverOperation CleaverOp CleaverA group of cyber actors utilizing infrastructure located in Iran have been conducting computer network exploitation activity against public and private U.S. organizations, including Cleared Defense Contractors (CDCs), academic institutions, and energy sector companies. This threat actor targets entities in the government, energy, and technology sectors that are located in or do business with Saudi Arabia.nation-stateIranG0003MuddyWaterTEMP.ZagrosStatic KittenThe MuddyWater attacks are primarily against Middle Eastern nations. However, we have also observed attacks against surrounding nations and beyond, including targets in India and the USA. MuddyWater attacks are characterized by the use of a slowly evolving PowerShell-based first stage backdoor we call “POWERSTATS”. Despite broad scrutiny and reports on MuddyWater attacks, the activity continues with only incremental changes to the tools and techniques.nation-stateIranG0069OilRigTwisted KittenCobalt GypsyOilRig is an Iranian threat group operating primarily in the Middle East by targeting organizations in this region that are in a variety of different industries; however, this group has occasionally targeted organizations outside of the Middle East as well. It also appears OilRig carries out supply chain attacks, where the threat group leverages the trust relationship between organizations to attack their primary targets.
OilRig is an active and organized threat group, which is evident based on their systematic targeting of specific organizations that appear to be carefully chosen for strategic purposes. Attacks attributed to this group primarily rely on social engineering to exploit the human rather than software vulnerabilities; however, on occasion this group has used recently patched vulnerabilities in the delivery phase of their attacks. The lack of software vulnerability exploitation does not necessarily suggest a lack of sophistication, as OilRig has shown maturity in other aspects of their operations. Such maturities involve:
-Organized evasion testing used the during development of their tools.
-Use of custom DNS Tunneling protocols for command and control (C2) and data exfiltration.
-Custom web-shells and backdoors used to persistently access servers.
OilRig relies on stolen account credentials for lateral movement. After OilRig gains access to a system, they use credential dumping tools, such as Mimikatz, to steal credentials to accounts logged into the compromised system. The group uses these credentials to access and to move laterally to other systems on the network. After obtaining credentials from a system, operators in this group prefer to use tools other than their backdoors to access the compromised systems, such as remote desktop and putty. OilRig also uses phishing sites to harvest credentials to individuals at targeted organizations to gain access to internet accessible resources, such as Outlook Web Access.
Since at least 2014, an Iranian threat group tracked by FireEye as APT34 has conducted reconnaissance aligned with the strategic interests of Iran. The group conducts operations primarily in the Middle East, targeting financial, government, energy, chemical, telecommunications and other industries. Repeated targeting of Middle Eastern financial, energy and government organizations leads FireEye to assess that those sectors are a primary concern of APT34. The use of infrastructure tied to Iranian operations, timing and alignment with the national interests of Iran also lead FireEye to assess that APT34 acts on behalf of the Iranian government.nation-stateIranG0049TA505SectorJ04SectorJ04 GroupTA505, the name given by Proofpoint, has been in the cybercrime business for at least four years. This is the group behind the infamous Dridex banking trojan and Locky ransomware, delivered through malicious email campaigns via Necurs botnet. Other malware associated with TA505 include Philadelphia and GlobeImposter ransomware families.RussiaG0092BackdoorDiplomacyBackDipCloudComputatingAn APT group that we are calling BackdoorDiplomacy, due to the main vertical of its victims, has been targeting Ministries of Foreign Affairs and telecommunication companies in Africa and the Middle East since at least 2017.G0135APT17Group 8AURORA PANDAFireEye described APT17 in a 2015 report as: 'APT17, also known as DeputyDog, is a China based threat group that FireEye Intelligence has observed conducting network intrusions against U.S. government entities, the defense industry, law firms, information technology companies, mining companies, and non-government organizations.'nation-stateChinaG0001DarkHotelDUBNIUMFallout TeamKaspersky described DarkHotel in a 2014 report as: '... DarkHotel drives its campaigns by spear-phishing targets with highly advanced Flash zero-day exploits that effectively evade the latest Windows and Adobe defenses, and yet they also imprecisely spread among large numbers of vague targets with peer-to-peer spreading tactics. Moreover, this crews most unusual characteristic is that for several years the Darkhotel APT has maintained a capability to use hotel networks to follow and hit selected targets as they travel around the world.'nation-stateKorea (Republic of)G0012El MacheteMachetemachete-aptEl Machete is one of these threats that was first publicly disclosed and named by Kaspersky here. We’ve found that this group has continued to operate successfully, predominantly in Latin America, since 2014. All attackers simply moved to new C2 infrastructure, based largely around dynamic DNS domains, in addition to making minimal changes to the malware in order to evade signature-based detection.UnknownG0095HigaisaThe organization often uses important North Korean time nodes such as holidays and North Korea to conduct fishing activities. The bait includes New Year blessings, Lantern blessings, North Korean celebrations, and important news, overseas personnel contact lists and so on. In addition, the attack organization also has the attack capability of the mobile terminal. The targets of the attack also include diplomatic entities related to North Korea (such as embassy officials in various places), government officials, human rights organizations, North Korean residents abroad, and traders. The victim countries currently monitored include China, North Korea, Japan, Nepal, Singapore, Russia, Poland, Switzerland, etc.nation-stateKorea (Republic of)G0126ProjectSauronStriderSauronProjectSauron is the name for a top level modular cyber-espionage platform, designed to enable and manage long-term campaigns through stealthy survival mechanisms coupled with multiple exfiltration methods. Technical details show how attackers learned from other extremely advanced actors in order to avoid repeating their mistakes. As such, all artifacts are customized per given target, reducing their value as indicators of compromise for any other victim. Usually APT campaigns have a geographical nexus, aimed at extracting information within a specific region or from a given industry. That usually results in several infections in countries within that region, or in the targeted industry around the world. Interestingly, ProjectSauron seems to be dedicated to just a couple of countries, focused on collecting high value intelligence by compromising almost all key entities it could possibly reach within the target area. The name, ProjectSauron reflects the fact that the code authors refer to ‘Sauron’ in the Lua scripts.nation-stateUSAG0041
Targeting Azerbaijan & the Caucasus
regional priorityDeadlockDeadlock is an active ransomware/extortion group tracked on ransomware.live from the victims it lists on its public leak site.crime93 victims · active 21dSandwormQuedaghVOODOO BEARThis threat actor targets industrial control systems, using a tool called Black Energy, associated with electricity and power generation for espionage, denial of service, and data destruction purposes. Some believe that the threat actor is linked to the 2015 compromise of the Ukrainian electrical grid and a distributed denial of service prior to the Russian invasion of Georgia. Believed to be responsible for the 2008 DDoS attacks in Georgia and the 2015 Ukraine power grid outagenation-stateRussiaG0034Inception FrameworkClean UrsaCloud AtlasThis threat actor uses spear-phishing techniques to target private-sector energy, defense, aerospace, research, and media organizations and embassies in Africa, Europe, and the Middle East, for the purpose of espionage.nation-stateRussiaG0100qilinQilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.crime294 victims · active 14dincransomInc RansomGOLD IONICINC Ransom is a prolific ransomware-as-a-service operation active since July 2023 that systematically targets healthcare, government, education, and manufacturing sectors in North America and Europe, having posted over 200 victims in 2025 alone with no sector off-limits.crime90 victims · active 14d · G1032DragonForceDragonForce is a hacktivist group based in Malaysia that has been involved in cyberattacks targeting government institutions and commercial organizations in India. They have also targeted websites affiliated with Israel and have shown support for pro-Palestinian causes. The group has been observed using defacement attacks, distributed denial-of-service attacks, and data leaks as part of their campaigns. DragonForce Malaysia has demonstrated an ability to adapt and evolve their tactics over time.MY76 victims · active 15d
All threat actors
800#8
A100
- Ababil of Minab
- Abrahams_Ax
- abyss
- Actor240524
- adminlocker
- Adrastea
- AeroBlade
- Aggressive Inventory Zombies
- aGl0bGVyCg
- AiLock
- ako
- ALLANITE
- ALP-001
- Alpha Spider
- alphalocker
- alphv
- Altahrea Team
- ALTDOS
- Altoufan Team
- Amaranth-Dragon
- Amethyst Rain
- ANDROMEDA SPIDER
- Angry Likho
- Anonymous KSA
- Anonymous Sudan
- Anonymous64
- ANTHROPOID SPIDER
- Antlion
- anubis
- Aoqin Dragon
- apos
- AppMilad
- APT-C-12
- APT-C-27
- APT-C-34
- APT-C-36
- APT-C-60
- APT.3102
- APT1
- APT10
- APT12
- APT14
- APT15
- APT16
- APT17
- APT18
- APT19
- APT2
- APT20
- APT21
- APT22
- APT23
- APT24
- APT26
- APT27
- APT28
- APT29
- APT3
- APT30
- APT31
- APT32
- APT33
- APT35
- APT37
- APT39
- APT4
- APT40
- APT41
- APT42
- APT43
- APT45
- APT5
- APT6
- APT73
- APT9
- APTIran
- Aptlock
- ArcaneDoor
- arcusmedia
- argonauts
- AridViper
- arkana
- Armored Likho
- arvinclub
- Aslan Neferler Tim
- Asnarök
- AtlasCross
- atomsilo
- Attor
- AuditTeam
- aurora
- avaddon
- Avivore
- avos
- avoslocker
- Awaken Likho
- aware
- Ayyıldız Tim
- aztroteam
- AzzaSec
B78
- babuk
- babuk2
- babyduck
- BackdoorDiplomacy
- BadRory
- Bahamut
- BAMBOO SPIDER
- BANISHED KITTEN
- Barracuda
- BatShadow
- BazarCall
- Bearlyfy
- beast
- Beijing Group
- BelialDemon
- Belsen Group
- benzona
- bert
- bianlian
- BiBiGun
- BIG PANDA
- Bignosa
- BITWISE SPIDER
- Black X
- Blackatom
- blackbasta
- blackbyte
- Blackfield
- Blackgear
- BlackJack
- blacklock
- BlackMaskers
- blackmatter
- Blackmeta
- blacknevas
- BlackOasis
- blackout
- blackshrantac
- blacksuit
- Blacktail
- BlackTech
- blacktor
- blackwater
- Blackwood
- BladedFeline
- BladeHawk
- Blue Mockingbird
- Blue Termite
- Blue Tsunami
- BlueBottle
- bluebox
- BlueHornet
- bluelocker
- bluesky
- BlueWhale
- Bohrium
- bonacigroup
- Bondnet
- Booba Project
- Boolka
- BOSON SPIDER
- BOSS SPIDER
- Boulder Bear
- bqtlock
- BrainCipher
- bravox
- BrazenBamboo
- BreachLaboratory
- BRONZE EDGEWOOD
- BRONZE HIGHLAND
- BRONZE SPIRAL
- BRONZE SPRING
- BRONZE STARLIGHT
- BRONZE VAPOR
- brotherhood
- Budminer
- BuhTrap
- ByteToBreach
C102
- cactus
- Cadelle
- Caliente Bandits
- Callisto
- Calypso
- Camaro Dragon
- Caracal Kitten
- Caramel Tsunami
- Carderbee
- CardinalLizard
- Careto
- Carmine Tsunami
- CashRewindo
- Cavern Manticore
- cephalus
- CeranaKeeper
- ChainedShark
- Chamelgang
- chaos
- Charming Kitten
- Chaya_004
- cheers
- Chernovite
- chilelocker
- Chimera
- chort
- Chronus Group
- CHRYSENE
- CiberInteligenciaSV
- cicada3301
- ciphbit
- cipherforce
- CIRCUS SPIDER
- CL-STA-0043
- CL-STA-0048
- CL-STA-1009
- CL-STA-1020
- CL-STA-1087
- CL-UNK-1068
- Cleaver
- Clever Kitten
- cloak
- CLOCKWORK SPIDER
- clop
- CloudSorcerer
- CMDOrganization
- Cobalt
- COBALT JUNO
- COBALT KATANA
- Codefinger
- Coinbase Cartel
- coinbasecartel
- Cold River
- ComicForm
- Common Raven
- Conference Crew
- Confucious
- Confucius
- Conquerors Electronic Army
- Contagious Interview
- ContFR
- conti
- cooming
- Copy-Paste
- CopyKittens
- CoralRaider
- Corsair Jackal
- Cosmic Lynx
- CosmicBeetle
- CostaRicto
- Cotton Sandstorm
- CoughingDown
- crazyhunter
- Crimson Collective
- crosslock
- CRPxO
- cry0
- crylock
- cryp70n1c0d3
- cryptbb
- cryptnet
- crypto24
- CryptoChameleon
- CRYSTALRAY
- cuba
- Cuboid Sandstorm
- Curious Gorge
- Curly COMrades
- Cutting Kitten
- Cyber Alliance
- Cyber Army of Russia Reborn
- Cyber Av3ngers
- Cyber Berkut
- Cyber Caliphate Army
- Cyber fighters of Izz Ad-Din Al Qassam
- Cyber Islamic Resistance
- Cyber Partisans
- Cyber Serp
- Cyber Toufan
- Cyber.Anarchy.Squad
- CyberNiggers
- cyclops
D75
- D1R
- d4rk4rmy
- DAGGER PANDA
- dagonlocker
- daixin
- Daixin Team
- Dalbit
- dAn0n
- Dancing Salome
- DangerousSavanna
- Danti
- Dark Basin
- Dark Caracal
- Dark Project
- darkangels
- darkbit
- DarkCasino
- DarkGaboon
- DarkHotel
- DarkHydrus
- darkleakmarket
- DarkMatter
- DarkPink
- darkpower
- DarkRaaS
- darkrace
- darkside
- DarkSpectre
- darkvault
- DarkVishnya
- datacarry
- datakeeper
- dataleak
- Deadeye Jackal
- Deadlock
- DefrayX
- Denim Tsunami
- desolator
- Desorden Group
- DEV-0147
- DEV-0270
- DEV-0569
- DEV-0586
- DEV-0928
- DEV-0950
- DEV-1028
- devman
- DEXTOROUS SPIDER
- diavol
- DiceyF
- DieNet
- direwolf
- dispossessor
- DIZZY PANDA
- DNSpionage
- Domestic Kitten
- donex
- donutleaks
- Doommageddon
- DOPPEL SPIDER
- doppelpaymer
- DragonBreath
- Dragonbridge
- DragonForce
- DragonOK
- DragonRank
- dragonransomware
- DragonSpark
- dread
- DriftingCloud
- DriveSurge
- DUNGEON SPIDER
- dunghill
- Dust Storm
- DustSquad
E47
- Earth Alux
- Earth Baxia
- Earth Berberoka
- Earth Estries
- Earth Freybug
- Earth Kapre
- Earth Kitsune
- Earth Krahang
- Earth Kurma
- Earth Lamia
- Earth Longzhi
- Earth Lusca
- Earth Naga
- Earth Wendigo
- Earth Yako
- EC2 Grouper
- ech0raix
- Eclipse
- Edalat-e Ali
- Educated Manticore
- El Machete
- ElDorado
- ELECTRIC PANDA
- ELOQUENT PANDA
- ELUSIVE COMET
- embargo
- Emperador
- ENERGETIC BEAR
- entropy
- ep918
- Equation
- Equation Group
- esxiargs
- Ethics
- Evasive Panda
- everest
- Evil Corp
- Evilbyte
- Evilnum
- EvilPost
- EvilTraffic
- EvilWeb
- ExCobalt
- ExfilSquad
- exitium
- exorcist
- EXOTIC LILY
F33
G72
- GALLIUM
- Gallmaker
- GamaCopy
- Gamaredon Group
- GambleForce
- Gammax
- GC01
- GC02
- GCMAN
- GDLockerSec
- Gelsemium
- genesis
- Ghost Jackal
- GHOST STADIUM
- GhostEmperor
- GhostNet
- GhostR
- GhostRedirector
- GhostSec
- Ghostwriter
- GIBBERISH PANDA
- Gitloker
- global
- Global Secret Group
- GlobalSecretGroup
- Gnosticplayers
- GOBLIN PANDA
- GodDamn ransomwhere
- GOFFEE
- GOLD BURLAP
- GOLD CABIN
- GOLD DUPONT
- GOLD EVERGREEN
- GOLD FAIRFAX
- GOLD FLANDERS
- GOLD GALLEON
- GOLD GARDEN
- GOLD MANSARD
- GOLD NORTHFIELD
- GOLD PRELUDE
- GOLD REBELLION
- GOLD RIVERVIEW
- GOLD SKYLINE
- GOLD SOUTHFIELD
- GOLD SYMPHONY
- GOLD WATERFALL
- GOLD WINTER
- GoldenJackal
- GoldFactory
- GopherWhisper
- Gorilla
- GozNym
- Gray Sandstorm
- GrayBravo
- GrayCharlie
- Grayling
- GreedyBear
- Greenbug
- GreenSpot
- GREF
- GreyEnergy
- GreyVibe
- grief
- GRIM SPIDER
- groove
- Groundbait
- Group5
- GTFire
- GTG-1002
- Guacamaya
- gunra
- GURU SPIDER
H40
- Hacking Team
- hades
- HAFNIUM
- Hagga
- Handala
- haron
- HAZY TIGER
- Head Mare
- Helix
- hellcat
- helldown
- HellHounds
- hellogookie
- hellokitty
- Hellsing
- HenBox
- HexagonalRodent
- Hezb
- HiddenArt
- Higaisa
- HikkI-Chan
- hive
- HIVE-0145
- Hive0117
- Hive0137
- Hive0163
- HollowQuill
- holyghost
- HomeLand Justice
- Honeybee
- HookAds
- hotarus
- Houken
- HOUND SPIDER
- Houndstooth Typhoon
- HummingBad
- Hunt3r Kill3rs
- hunters
- HURRICANE PANDA
- Hyadina
I25
J8
K23
L21
M20
N7
O8
P14
Q2
R18
S35
- safepay
- SaintBear
- SAMURAI PANDA
- Sandman APT
- Sandworm
- Scarab
- Scarlet Mimic
- Scattered Spider
- Sea Turtle
- securotrop
- settra
- Shadow-Earth-053
- SHADOW-WATER-063
- ShadowByt3$
- SharpPanda
- ShinyHunters
- SideCopy
- Silence group
- silent
- Silent Chollima
- Silent Librarian
- SilentRansomGroup
- SilverTerrier
- SNOWGLOBE
- Sovcali
- Sowbug
- SpaceBears
- Stealth Falcon
- Stealth Mango and Tangelo
- Storm
- Storm-0501
- Storm-0558
- Storm-1175
- Storm-1567
- stormous
T27
U11
V9
W14
X1
Y2
Sources: MISP Galaxy + ransomware.live + MITRE ATT&CK, recent activity name-joined with our items. Roster 1,412 actors (130 active, 1361 tracked in the Caucasus) · updated 18 Aug 2026. Search covers the whole roster.