Threat groups D–F
23 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.
Daggerfly (Evasive Panda)
Also tracked asBRONZE HIGHLAND
Daggerfly is a People's Republic of China-linked APT entity active since at least 2012. Daggerfly has targeted individuals, government and NGO…
Dark Caracal
Dark Caracal is threat group that has been attributed to the Lebanese General Directorate of General Security (GDGS) and has operated since at least…
Darkhotel (DUBNIUM)
Also tracked asZigzag Hail
Darkhotel is a suspected South Korean threat group that has targeted victims primarily in East Asia since at least 2004. The group's name is based on…
DarkHydrus
DarkHydrus is a threat group that has targeted government agencies and educational institutions in the Middle East since at least 2016. The group…
DarkVishnya
DarkVishnya is a financially motivated threat actor targeting financial institutions in Eastern Europe. In 2017-2018 the group attacked at least 8…
Deep Panda (Shell Crew)
Also tracked asWebMasters · KungFu Kittens · PinkPanther and 1 more
Deep Panda is a suspected Chinese threat group known to target many industries, including government, defense, financial, and telecommunications. The…
Dragonfly (TEMP.Isotope)
Also tracked asDYMALLOY · Berserk Bear · TG-4192 and 5 more
Dragonfly is a cyber espionage group that has been attributed to Russia's Federal Security Service (FSB) Center 16. Active since at least 2010,…
DragonOK
DragonOK is a threat group that has targeted Japanese organizations with phishing emails. Due to overlapping TTPs, including similar custom tools,…
Earth Lusca (TAG-22)
Also tracked asCharcoal Typhoon · CHROMIUM · ControlX
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations…
Elderwood (Elderwood Gang)
Also tracked asBeijing Group · Sneaky Panda
Elderwood is a suspected Chinese cyber espionage group that was reportedly responsible for the 2009 Google intrusion known as Operation Aurora. The…
Ember Bear (UNC2589)
Also tracked asBleeding Bear · DEV-0586 · Cadet Blizzard and 2 more
Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main…
Equation
Equation is a sophisticated threat group that employs multiple remote access tools. The group is known to use zero-day exploits and has developed the…
Evilnum
Evilnum is a financially motivated threat group that has been active since at least 2018.
EXOTIC LILY
EXOTIC LILY is a financially motivated group that has been closely linked with Wizard Spider and the deployment of ransomware including Conti and…
Ferocious Kitten
Ferocious Kitten is a threat group that has primarily targeted Persian-speaking individuals in Iran since at least 2015.
FIN10
FIN10 is a financially motivated threat group that has targeted organizations in North America since at least 2013 through 2016. The group uses…
FIN13 (Elephant Beetle)
FIN13 is a financially motivated cyber threat group that has targeted the financial, retail, and hospitality industries in Mexico and Latin America,…
FIN4
FIN4 is a financially-motivated threat group that has targeted confidential information related to the public financial market, particularly…
FIN5
FIN5 is a financially motivated threat group that has targeted personally identifiable information and payment card information. The group has been…
FIN6 (Magecart Group 6)
Also tracked asITG08 · Skeleton Spider · TAAL and 1 more
FIN6 is a cyber crime group that has stolen payment card data and sold it for profit on underground marketplaces. This group has aggressively…
FIN7 (GOLD NIAGARA)
Also tracked asITG14 · Carbon Spider · ELBRUS and 1 more
FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software,…
FIN8 (Syssphinx)
FIN8 is a financially motivated threat group that has been active since at least January 2016, and known for targeting organizations in the…
Fox Kitten (UNC757)
Also tracked asParisite · Pioneer Kitten · RUBIDIUM and 1 more
Fox Kitten is threat actor with a suspected nexus to the Iranian government that has been active since at least 2017 against entities in the Middle…
Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator