APT-Gruppen & Threat Actors
Threat-Actor-Lage im Überblick
Kanonische APT-Gruppen-Stammdaten aus der MISP-Galaxy-Spine, angereichert mit MITRE-ATT&CK-Techniken, eingesetzter Software und öffentlich verlinkten Berichten. Hersteller-Namensschemata (Microsoft Wetter, CrowdStrike Tiere) werden als Aliase mitgeführt — eine Suche nach „Cozy Bear“ findet APT29.
Filter
Gelistete Gruppen
1.012 Gruppen
1937CN
CNUnbekannt1937CN is a Chinese hacking group that has been active since at least 2013. The group is known for targeting Vietnamese organizations, including government agencies, businesses, and media outlets. 1937CN has been linked to a number of hi…
313 Team
IQUnbekannt313 Team is an Iraq-based threat actor that has conducted coordinated DDoS campaigns targeting multiple government servers in the UAE, Kuwait, and Romania, often in response to political statements. They have claimed responsibility for s…
Ababil of Minab
IRUnbekanntAbabil of Minab is an emerging pro-Iranian hacktivist group with a limited public profile and little verifiable prior activity in threat intelligence reporting. The group claims responsibility for a cyberattack and allegedly possesses ad…
Actor240524
UnbekanntActor240524 is a newly identified APT group that targeted Azerbaijani and Israeli diplomats through spear-phishing emails to steal sensitive data. The group employs a Trojan program known as ABCloader and ABCsync, demonstrating capabilit…
Adrastea
UnbekanntAdrastea is a threat actor who has been active on cybercrime forums, claiming to have breached organizations like MBDA and offering stolen data for sale. They describe themselves as a group of independent cybersecurity experts and resear…
AeroBlade
UnbekanntAeroBlade is a previously unknown threat actor that has been targeting an aerospace organization in the United States. Their objective appears to be conducting commercial and competitive cyber espionage. They employ spear-phishing as a d…
Aggressive Inventory Zombies
UnbekanntAggressive Inventory Zombies is a threat actor involved in a large-scale phishing and pig-butchering network targeting retail brands and cryptocurrency users. They create fraudulent sites using a popular website template that scrapes pro…
AIZ
ALLANITE
UnklarUnbekanntAdversaries abusing ICS (based on Dragos Inc adversary list). ALLANITE accesses business and industrial control (ICS) networks, conducts reconnaissance, and gathers intelligence in United States and United Kingdom electric utility sector…
Palmetto Fusion · Allanite
Alpha Spider
UnbekanntALPHA SPIDER is a threat actor known for developing and operating the Alphv ransomware as a service. They have been observed using novel offensive techniques, such as exploiting software vulnerabilities and leveraging legitimate administ…
ALPHV Ransomware Group
Altahrea Team
IQUnbekanntAltahrea Team is a pro-Iranian hacking group that has been active since at least 2020. The group has claimed responsibility for a number of cyberattacks, including DDoS attacks against Israeli websites, a hack of the Israel Airports Auth…
ALTDOS
UnbekanntALTDOS is a threat actor group that has targeted entities in Southeast Asia, including Singapore, Thailand, and Malaysia. They have been involved in data breaches of companies in various sectors, such as real estate and retail, compromis…
Altoufan Team
UnbekanntALTOUFAN TEAM is a politically motivated hacktivist group with anti-Zionism, anti-monarchy, and pro-14-February movement sentiments. They have targeted government agencies and organizations in Bahrain and Israel, claiming to support poli…
Amaranth-Dragon
CNUnbekanntAmaranth-Dragon is a previously untracked threat actor assessed to be closely linked to the China-affiliated APT 41 ecosystem, exhibiting similar tooling and operational patterns. The group demonstrated technical maturity by rapidly oper…
ANDROMEDA SPIDER
UnbekanntAngry Likho
RUUnbekanntAngry Likho is an APT group that has been active since 2023, primarily targeting large organizations and government agencies in Russia and Belarus. Their attacks typically involve spear-phishing emails with malicious attachments, such as…
Sticky Werewolf
Anonymous64
TWUnbekanntAnonymous 64 is a group accused by China's national security ministry of attempting to gain control of web portals, outdoor electronic screens, and network television. The Ministry of State Security claims that Anonymous 64 is linked to…
Anonymous 64
Anonymous KSA
UnbekanntAnonymous KSA is a Saudi hacking group that has executed cyber attacks targeting Indian institutions, including a significant breach of UIDAI's data storage units, leading to access to sensitive information and system disruption. The gro…
Anonymous Sudan
UnklarUnbekanntSince January 23, 2023, a threat actor identifying as "Anonymous Sudan" has been conducting denial of service (DDoS) attacks against multiple organizations in Sweden. This group claims to be "hacktivists," politically motivated hackers f…
ANTHROPOID SPIDER
UnbekanntPublicly known as 'EmpireMonkey', ANTHROPOID SPIDER conducted phishing campaigns in February and March 2019, spoofing French, Norwegian and Belizean financial regulators and institutions. These campaigns used macro-enabled Microsoft docu…
Empire Monkey · CobaltGoblin
Antlion
CNUnbekanntAntlion is a Chinese state-backed advanced persistent threat (APT) group, who has been targeting financial institutions in Taiwan. This persistent campaign has lasted over the course of at least 18 months.
Aoqin Dragon
CNUnbekanntSentinelLabs has uncovered a cluster of activity beginning at least as far back as 2013 and continuing to the present day, primarily targeting organizations in Southeast Asia and Australia. They assess that the threat actor's primary foc…
UNC94
AppMilad
IRUnbekanntAppMilad is an Iranian hacking group that has been identified as the source of a spyware campaign called RatMilad. This spyware is designed to silently infiltrate victims' devices and gather personal and corporate information, including…
APT1
CNStaatlichUnbekanntPLA Unit 61398 (Chinese: 61398部队, Pinyin: 61398 bùduì) is the Military Unit Cover Designator (MUCD)[1] of a People's Liberation Army advanced persistent threat unit that has been alleged to be a source of Chinese computer hacking attacks
COMMENT PANDA · PLA Unit 61398 · Comment Crew · Byzantine Candor …+6
APT10
CNStaatlichUnbekanntmenuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the Chinese Ministry of State Security's (MSS) Tianjin State Security Bureau and worked for t…
STONE PANDA · Menupass Team · happyyongzi · POTASSIUM …+10
APT12
CNStaatlichUnbekanntA group of China-based attackers, who conducted a number of spear phishing attacks in 2013.
NUMBERED PANDA · TG-2754 · BeeBus · Group 22 …+7
APT14
CNStaatlichUnbekanntPLA Navy Anchor Panda is an adversary that CrowdStrike has tracked extensively over the last year targeting both civilian and military maritime operations in the green/brown water regions primarily in the area of operations of the South…
ANCHOR PANDA · QAZTeam · ALUMINUM
APT15
CNStaatlichUnbekanntThis threat actor uses phishing techniques to compromise the networks of foreign ministries of European countries for espionage purposes.
VIXEN PANDA · Ke3Chang · Playful Dragon · Metushy …+10
APT16
CNStaatlichUnbekanntBetween November 26, 2015, and December 1, 2015, known and suspected China-based APT groups launched several spear-phishing attacks targeting Japanese and Taiwanese organizations in the high-tech, government services, media and financial…
SVCMONDR
APT17
CNStaatlichUnbekanntFireEye described APT17 in a 2015 report as: 'APT17, also known as DeputyDog, is a China based threat group that FireEye Intelligence has observed conducting network intrusions against U.S. government entities, the defense industry, law…
Group 8 · AURORA PANDA · Hidden Lynx · Tailgater Team …+6
APT18
CNStaatlichUnbekanntWekby was described by Palo Alto Networks in a 2015 report as: 'Wekby is a group that has been active for a number of years, targeting various industries such as healthcare, telecommunications, aerospace, defense, and high tech. The grou…
DYNAMITE PANDA · TG-0416 · SCANDIUM · PLA Navy …+2
APT19
CNStaatlichUnbekanntAdversary group targeting financial, technology, non-profit organisations.
DEEP PANDA · Codoso · WebMasters · KungFu Kittens …+9
APT2
CNStaatlichUnbekanntPutter Panda were the subject of an extensive report by CrowdStrike, which stated: 'The CrowdStrike Intelligence team has been tracking this particular unit since2012, under the codename PUTTER PANDA, and has documented activity dating b…
PLA Unit 61486 · PUTTER PANDA · MSUpdater · 4HCrew …+3
APT20
CNUnbekanntWe’ve uncovered some new data and likely attribution regarding a series of APT watering hole attacks this past summer. Watering hole attacks are an increasingly popular component of APT campaigns, as many people are more aware of spear p…
VIOLIN PANDA · TH3Bug · Crawling Taurus
APT21
CNStaatlichUnbekanntHAMMER PANDA · TEMP.Zhenbao · NetTraveler
APT22
CNUnbekanntSuckfly is a China-based threat group that has been active since at least 2014
Suckfly · BRONZE OLIVE · Group 46
APT23
CNUnbekanntTrendMicro described Tropic Trooper in a 2015 report as: 'Taiwan and the Philippines have become the targets of an ongoing campaign called Operation TropicTrooper. Active since 2012, the attackers behind the campaign haveset their sights…
PIRATE PANDA · KeyBoy · Tropic Trooper · BRONZE HOBART …+2
APT24
CNUnbekanntThe Pitty Tiger group has been active since at least 2011. They have been seen using HeartBleed vulnerability in order to directly get valid credentials
PITTY PANDA · Temp.Pittytiger
APT26
CNUnbekanntJerseyMikes · TURBINE PANDA · BRONZE EXPRESS · TECHNETIUM …+1
APT27
CNStaatlichUnbekanntA China-based actor that targets foreign embassies to collect data on government, defence, and technology sectors.
GreedyTaotie · TG-3390 · EMISSARY PANDA · TEMP.Hippo …+11
APT28
RUStaatlichUnbekanntThe Sofacy Group (also known as APT28, Pawn Storm, Fancy Bear and Sednit) is a cyber espionage group believed to have ties to the Russian government. Likely operating since 2007, the group is known to target government, military, and sec…
Pawn Storm · FANCY BEAR · Sednit · SNAKEMACKEREL …+22
APT29
RUStaatlichUnbekanntA 2015 report by F-Secure describe APT29 as: 'The Dukes are a well-resourced, highly dedicated and organized cyberespionage group that we believe has been working for the Russian Federation since at least 2008 to collect intelligence in…
Group 100 · COZY BEAR · The Dukes · Minidionis …+12
APT3
CNStaatlichUnbekanntSymantec described UPS in 2016 report as: 'Buckeye (also known as APT3, Gothic Panda, UPS Team, and TG-0110) is a cyberespionage group that is believed to have been operating for well over half a decade. Traditionally, the group attacke…
GOTHIC PANDA · TG-0110 · Group 6 · UPS …+6
APT30
CNStaatlichUnbekanntAPT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups do not appear to be exact matches
APT31
CNUnbekanntFireEye characterizes APT31 as an actor specialized on intellectual property theft, focusing on data and projects that make a particular organization competetive in its field. Based on available data (April 2016), FireEye assesses that A…
ZIRCONIUM · JUDGMENT PANDA · BRONZE VINEWOOD · Red keres …+2
APT.3102
CNUnbekanntAPT32
VNStaatlichUnbekanntCyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple industries and have also targeted foreign governments, dissidents, and journalists.…
OceanLotus Group · Ocean Lotus · OceanLotus · Cobalt Kitty …+11
APT33
IRStaatlichUnbekanntOur analysis reveals that APT33 is a capable group that has carried out cyber espionage operations since at least 2013. We assess APT33 works at the behest of the Iranian government.
APT 33 · Elfin · MAGNALLIUM · Refined Kitten …+5
APT35
IRUnbekanntFireEye has identified APT35 operations dating back to 2014. APT35, also known as the Newscaster Team, is a threat group sponsored by the Iranian government that conducts long term, resource-intensive operations to collect strategic inte…
Newscaster Team · Magic Hound · Phosphorus · Mint Sandstorm …+3
APT37
KPUnbekanntAPT37 has likely been active since at least 2012 and focuses on targeting the public and private sectors primarily in South Korea. In 2017, APT37 expanded its targeting beyond the Korean peninsula to include Japan, Vietnam and the Middle…
APT 37 · Group 123 · Group123 · InkySquid …+11
APT39
IRUnbekanntAPT39 was created to bring together previous activities and methods used by this actor, and its activities largely align with a group publicly referred to as "Chafer." However, there are differences in what has been publicly reported due…
Chafer · REMIX KITTEN · COBALT HICKMAN · Radio Serpens …+3
APT4
CNStaatlichUnbekanntPLA Navy · MAVERICK PANDA · BRONZE EDISON · SODIUM …+1
APT40
CNStaatlichUnbekanntLeviathan is an espionage actor targeting organizations and high-value targets in defense and government. Active since at least 2014, this actor has long-standing interest in maritime industries, naval defense contractors, and associated…
TEMP.Periscope · TEMP.Jumper · Leviathan · BRONZE MOHAWK …+9
APT41
CNUnbekanntAPT41 is a prolific cyber threat group that carries out Chinese state-sponsored espionage activity in addition to financially motivated activity potentially outside of state control.
TA415 · Blackfly · Grayfly · LEAD …+14
APT42
IRStaatlichUnbekanntIranian state-sponsored cyber espionage group tasked with conducting information collection and surveillance operations against individuals and organizations of strategic interest to the Iranian government.
UNC788 · CALANQUE
APT43
Unbekannt• APT43 is a prolific cyber operator that supports the interests of the North Korean regime. The group combines moderately-sophisticated technical capabilities with aggressive social engineering tactics, especially against South Korean a…
APT45
KPUnbekanntAPT45 is a North Korean cyber threat actor that has been active since at least 2009. They have conducted espionage campaigns targeting government agencies and defense industries, as well as financially-motivated operations, including ran…
APT5
CNUnbekanntWe have observed one APT group, which we call APT5, particularly focused on telecommunications and technology companies. More than half of the organizations we have observed being targeted or breached by APT5 operate in these sectors. Se…
KEYHOLE PANDA · MANGANESE · BRONZE FLEETWOOD · TEMP.Bottle …+2
APT6
CNUnbekanntThe FBI issued a rare bulletin admitting that a group named Advanced Persistent Threat 6 (APT6) hacked into US government computer systems as far back as 2011 and for years stole sensitive data. The FBI alert was issued in February and w…
1.php Group
APT73
UnbekanntAPT73 is a ransomware group that has publicly identified 12 victims and launched its data leak site on April 25th. The DLS bears a striking resemblance to that of LockBit, likely to leverage LockBit's reputation and attract potential aff…
Eraleig
APT9
CNUnbekanntAPT9 engages in cyber operations where the goal is data theft, usually focusing on the data and projects that make a particular organization competitive within its field. APT9 was historically very active in the pharmaceuticals and biote…
NIGHTSHADE PANDA · Red Pegasus · Group 27