Threat groups B–C
16 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.
BackdoorDiplomacy
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign…
BITTER (T-APT-17)
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and…
BlackByte (Hecamede)
BlackByte is a ransomware threat actor operating since at least 2021. BlackByte is associated with several versions of ransomware also labeled…
BlackOasis
BlackOasis is a Middle Eastern threat group that is believed to be a customer of Gamma Group. The group has shown interest in prominent figures in…
BlackTech (Palmerworm)
BlackTech is a suspected Chinese cyber espionage group that has primarily targeted organizations in East Asia--particularly Taiwan, Japan, and Hong…
Blue Mockingbird
Blue Mockingbird is a cluster of observed activity involving Monero cryptocurrency-mining payloads in dynamic-link library (DLL) form on Windows…
BRONZE BUTLER (REDBALDKNIGHT)
Also tracked asTick
BRONZE BUTLER is a cyber espionage group with likely Chinese origins that has been active since at least 2008. The group primarily targets Japanese…
Carbanak (Anunak)
Carbanak is a cybercriminal group that has used Carbanak malware to target financial institutions since at least 2013. Carbanak may be linked to…
Chimera
Chimera is a suspected China-based threat group that has been active since at least 2018 targeting the semiconductor industry in Taiwan as well as…
Cinnamon Tempest (DEV-0401)
Also tracked asEmperor Dragonfly · BRONZE STARLIGHT
Cinnamon Tempest is a China-based threat group that has been active since at least 2021 deploying multiple strains of ransomware based on the leaked…
Cleaver (Threat Group 2889)
Also tracked asTG-2889
Cleaver is a threat group that has been attributed to Iranian actors and is responsible for activity tracked as Operation Cleaver. Strong…
Cobalt Group (GOLD KINGSWOOD)
Also tracked asCobalt Gang · Cobalt Spider
Cobalt Group is a financially motivated threat group that has primarily targeted financial institutions since at least 2016. The group has conducted…
Confucius (Confucius APT)
Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government…
Contagious Interview (DeceptiveDevelopment)
Also tracked asGwisin Gang · Tenacious Pungsan · DEV#POPPER and 2 more
Contagious Interview is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated…
CopyKittens
CopyKittens is an Iranian cyber espionage group that has been operating since at least 2013. It has targeted countries including Israel, Saudi…
CURIUM (Crimson Sandstorm)
Also tracked asTA456 · Tortoise Shell · Yellow Liderc
CURIUM is an Iranian threat group, first reported in September 2019 and active since at least July 2018, targeting IT service providers in the Middle…
Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator