NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups B–C

16 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. BackdoorDiplomacy

    G013515 techniques5 tools & malware

    BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign…

  2. BITTER (T-APT-17)

    G100216 techniques1 tools & malware

    BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and…

  3. BlackByte (Hecamede)

    G104348 techniques8 tools & malware

    BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled…

  4. BlackOasis

    G00631 techniques

    BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in…

  5. BlackTech (Palmerworm)

    G0098China14 techniques6 tools & malware

    BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong…

  6. Blue Mockingbird

    G010822 techniques2 tools & malware1 live indicators

    Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows…

  7. BRONZE BUTLER (REDBALDKNIGHT)

    G0060ChinaEspionage40 techniques14 tools & malware

    Also tracked asTick

    BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese…

  8. Carbanak (Anunak)

    G0008Financial gain9 techniques4 tools & malware5 live indicators

    Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to…

  9. Chimera

    G0114China59 techniques6 tools & malware

    Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as…

  10. Cinnamon Tempest (DEV-0401)

    G1021China19 techniques8 tools & malware1,636 live indicators

    Also tracked asEmperor Dragonfly · BRONZE STARLIGHT

    Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked…

  11. Cleaver (Threat Group 2889)

    G0003IranEspionage5 techniques4 tools & malware

    Also tracked asTG-2889

    Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong…

  12. Cobalt Group (GOLD KINGSWOOD)

    G008034 techniques6 tools & malware

    Also tracked asCobalt Gang · Cobalt Spider

    Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted…

  13. Confucius (Confucius APT)

    G014219 techniques1 tools & malware

    Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government…

  14. Contagious Interview (DeceptiveDevelopment)

    G1052North Korea54 techniques4 tools & malware47 live indicators

    Also tracked asGwisin Gang · Tenacious Pungsan · DEV#POPPER and 2 more

    Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated…

  15. CopyKittens

    G0052IranEspionage8 techniques4 tools & malware

    CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi…

  16. CURIUM (Crimson Sandstorm)

    G1012IranEspionage19 techniques1 tools & malware

    Also tracked asTA456 · Tortoise Shell · Yellow Liderc

    CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle…

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator