NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups D–F

23 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. Daggerfly (Evasive Panda)

    G1034ChinaEspionage17 techniques6 tools & malware

    Also tracked asBRONZE HIGHLAND

    Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO…

  2. Dark Caracal

    G007012 techniques3 tools & malware124 live indicators

    Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least…

  3. Darkhotel (DUBNIUM)

    G0012South KoreaEspionage24 techniques

    Also tracked asZigzag Hail

    Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on…

  4. DarkHydrus

    G00797 techniques3 tools & malware

    DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group…

  5. DarkVishnya

    G010510 techniques2 tools & malware

    DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8…

  6. Deep Panda (Shell Crew)

    G0009ChinaEspionage10 techniques7 tools & malware1 live indicators

    Also tracked asWebMasters · KungFu Kittens · PinkPanther and 1 more

    Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The…

  7. Dragonfly (TEMP.Isotope)

    G0035RussiaEspionage56 techniques10 tools & malware

    Also tracked asDYMALLOY · Berserk Bear · TG-4192 and 5 more

    Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010,…

  8. DragonOK

    G0017Espionage2 tools & malware

    DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools,…

  9. Earth Lusca (TAG-22)

    G1006China44 techniques9 tools & malware

    Also tracked asCharcoal Typhoon · CHROMIUM · ControlX

    Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations…

  10. Elderwood (Elderwood Gang)

    G0066ChinaEspionage9 techniques9 tools & malware

    Also tracked asBeijing Group · Sneaky Panda

    Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. The…

  11. Ember Bear (UNC2589)

    G1003RussiaSabotage47 techniques11 tools & malware2 live indicators

    Also tracked asBleeding Bear · DEV-0586 · Cadet Blizzard and 2 more

    Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main…

  12. Equation

    G00204 techniques

    Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the…

  13. Evilnum

    G012011 techniques3 tools & malware36 live indicators

    Evilnum is a financially motivated threat group that has been active since at least 2018.

  14. EXOTIC LILY

    G101115 techniques2 tools & malware573 live indicators

    EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and…

  15. Ferocious Kitten

    G0137Iran6 techniques2 tools & malware

    Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.

  16. FIN10

    G005111 techniques1 tools & malware

    FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses…

  17. FIN13 (Elephant Beetle)

    G101653 techniques4 tools & malware

    FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America,…

  18. FIN4

    G008512 techniques

    FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly…

  19. FIN5

    G005311 techniques6 tools & malware

    FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been…

  20. FIN6 (Magecart Group 6)

    G003740 techniques12 tools & malware86 live indicators

    Also tracked asITG08 · Skeleton Spider · TAAL and 1 more

    FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively…

  21. FIN7 (GOLD NIAGARA)

    G0046Financial gain67 techniques19 tools & malware331 live indicators

    Also tracked asITG14 · Carbon Spider · ELBRUS and 1 more

    FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software,…

  22. FIN8 (Syssphinx)

    G006136 techniques11 tools & malware21 live indicators

    FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the…

  23. Fox Kitten (UNC757)

    G0117Iran41 techniques5 tools & malware299 live indicators

    Also tracked asParisite · Pioneer Kitten · RUBIDIUM and 1 more

    Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle…

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator