NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups A

29 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. admin@338

    G0018ChinaEspionage12 techniques7 tools & malware

    admin@338 is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted…

  2. Agrius (Pink Sandstorm)

    G1030Iran22 techniques9 tools & malware

    Also tracked asAMERICIUM · Agonizing Serpens · BlackShadow

    Agrius is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on…

  3. Ajax Security Team (Operation Woolen-Goldfish)

    G0130IranEspionage6 techniques2 tools & malware

    Also tracked asAjaxTM · Rocket Kitten · Flying Kitten and 1 more

    Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team…

  4. Akira (GOLD SAHARA)

    G102417 techniques8 tools & malware572 live indicators

    Also tracked asPUNK SPIDER · Howling Scorpius

    Akira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access…

  5. Andariel (Silent Chollima)

    G0138North KoreaEspionage12 techniques2 tools & malware1 live indicators

    Also tracked asPLUTONIUM · Onyx Sleet

    Andariel is a North Korean state-sponsored threat group that has been active since at least 2009. Andariel has primarily focused its…

  6. Aoqin Dragon

    G1007China9 techniques2 tools & malware

    Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted…

  7. AppleJeus (Gleaming Pisces)

    G1049North KoreaEspionage2 techniques

    Also tracked asCitrine Sleet · UNC1720 · UNC4736

    AppleJeus is a North Korean state-sponsored threat group attributed to the Reconnaissance General Bureau. Associated with the broader Lazarus Group…

  8. APT-C-23 (Mantis)

    G1028Espionage1 tools & malware1 live indicators

    Also tracked asArid Viper · Desert Falcon · TAG-63 and 3 more

    APT-C-23 is a threat group that has been active since at least 2014. APT-C-23 has primarily focused its operations on the Middle East, including…

  9. APT-C-36 (Blind Eagle)

    G0099Espionage38 techniques9 tools & malware3,293 live indicators

    Also tracked asTAG-144 · AguilaCiega · APT-Q-98

    APT-C-36 is a suspected South American threat group that has engaged in espionage and financially motivated operations since at least 2018. APT-C-36…

  10. APT1 (Comment Crew)

    G0006ChinaEspionage23 techniques17 tools & malware

    Also tracked asComment Group · Comment Panda

    APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd…

  11. APT12 (IXESHE)

    G0005ChinaEspionage5 techniques3 tools & malware

    Also tracked asDynCalc · Numbered Panda · DNSCALC

    APT12 is a threat group that has been attributed to China. The group has targeted a variety of victims including but not limited to media outlets,…

  12. APT16

    G0023ChinaEspionage1 techniques1 tools & malware

    APT16 is a China-based threat group that has launched spearphishing campaigns targeting Japanese and Taiwanese organizations.

  13. APT17 (Deputy Dog)

    G0025ChinaEspionage2 techniques1 tools & malware

    APT17 is a China-based threat group that has conducted network intrusions against U.S. government entities, the defense industry, law firms,…

  14. APT18 (TG-0416)

    G0026ChinaEspionage12 techniques5 tools & malware

    Also tracked asDynamite Panda · Threat Group-0416

    APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human…

  15. APT19 (Codoso)

    G0073ChinaEspionage21 techniques2 tools & malware

    Also tracked asC0d0so0 · Codoso Team · Sunshop Group

    APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical,…

  16. APT28 (IRON TWILIGHT)

    G0007RussiaEspionage93 techniques29 tools & malware165 live indicators

    Also tracked asSNAKEMACKEREL · Swallowtail · Group 74 and 11 more

    APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center…

  17. APT29 (IRON RITUAL)

    G0016RussiaEspionage66 techniques49 tools & malware1,689 live indicators

    Also tracked asIRON HEMLOCK · NobleBaron · Dark Halo and 10 more

    APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often…

  18. APT3 (Gothic Panda)

    G0022ChinaEspionage44 techniques6 tools & malware

    Also tracked asPirpi · UPS Team · Buckeye and 2 more

    APT3 is a China-based threat group that researchers have attributed to China's Ministry of State Security. This group is responsible for the…

  19. APT30

    G0013ChinaEspionage2 techniques5 tools & malware

    APT30 is a threat group suspected to be associated with the Chinese government. While Naikon shares some characteristics with APT30, the two groups…

  20. APT32 (SeaLotus)

    G0050VietnamEspionage78 techniques15 tools & malware6 live indicators

    Also tracked asOceanLotus · APT-C-00 · Canvas Cyclone and 1 more

    APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries…

  21. APT33 (HOLMIUM)

    G0064IranEspionage31 techniques16 tools & malware629 live indicators

    Also tracked asElfin · Peach Sandstorm

    APT33 is a suspected Iranian threat group that has carried out operations since at least 2013. The group has targeted organizations across multiple…

  22. APT37 (InkySquid)

    G0067North Korea29 techniques13 tools & malware17 live indicators

    Also tracked asScarCruft · Reaper · Group123 and 2 more

    APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in…

  23. APT38 (NICKEL GLADSTONE)

    G0082North KoreaEspionage56 techniques6 tools & malware313 live indicators

    Also tracked asBeagleBoyz · Bluenoroff · Stardust Chollima and 2 more

    APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance…

  24. APT39 (ITG07)

    G0087Iran53 techniques11 tools & malware

    Also tracked asChafer · Remix Kitten

    APT39 is one of several names for cyber espionage activity conducted by the Iranian Ministry of Intelligence and Security (MOIS) through the front…

  25. APT41 (Wicked Panda)

    G0096China82 techniques32 tools & malware34 live indicators

    Also tracked asBrass Typhoon · BARIUM

    APT41 is a threat group that researchers have assessed as Chinese state-sponsored espionage group that also conducts financially-motivated…

  26. APT42

    G1044IranEspionage32 techniques2 tools & malware

    APT42 is an Iranian-sponsored threat group that conducts cyber espionage and surveillance. The group primarily focuses on targets in the Middle East…

  27. APT5 (Mulberry Typhoon)

    G1023China29 techniques13 tools & malware

    Also tracked asMANGANESE · BRONZE FLEETWOOD · Keyhole Panda and 1 more

    APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense…

  28. Aquatic Panda

    G0143China35 techniques6 tools & malware

    Aquatic Panda is a suspected China-based threat group with a dual mission of intelligence collection and industrial espionage. Active since at least…

  29. Axiom (Group 72)

    G0001ChinaEspionage16 techniques8 tools & malware

    Axiom is a suspected Chinese cyber espionage group that has targeted the aerospace, defense, government, manufacturing, and media sectors since at…

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator