Threat groups J–M
25 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.
Ke3chang (APT15)
Also tracked asMirage · Vixen Panda · GREF and 4 more
Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in…
Kimsuky (Black Banshee)
Also tracked asVelvet Chollima · Emerald Sleet · THALLIUM and 5 more
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially…
LAPSUS$ (DEV-0537)
Also tracked asStrawberry Tempest
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and…
Lazarus Group (Labyrinth Chollima)
Also tracked asHIDDEN COBRA · Guardians of Peace · ZINC and 2 more
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been…
LazyScripter
LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.
Leafminer (Raspite)
Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.
Leviathan (MUDCARP)
Also tracked asKryptonite Panda · Gadolinium · BRONZE MOHAWK and 4 more
Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security…
Lotus Blossom (DRAGONFISH)
Also tracked asSpring Dragon · RADIUM · Raspberry Typhoon and 2 more
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related…
LuminousMoth
LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile…
Machete (APT-C-43)
Also tracked asEl Machete
Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations…
Magic Hound (TA453)
Also tracked asCOBALT ILLUSION · Charming Kitten · ITG18 and 4 more
Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the…
Malteiro
Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group…
Medusa Group
Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a…
menuPass (Cicada)
Also tracked asPOTASSIUM · Stone Panda · APT10 and 4 more
menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the…
Metador
Metador is a suspected cyber espionage group that was first reported in September 2022. Metador has targeted a limited number of telecommunication…
MirrorFace (Earth Kasha)
MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on…
Moafee
Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee…
Mofang
Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been…
Molerats (Operation Molerats)
Also tracked asGaza Cybergang
Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the…
Moonstone Sleet (Storm-1789)
Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously…
Moses Staff (DEV-0500)
Also tracked asMarigold Sandstorm
Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. Moses Staff openly…
MoustachedBouncer
MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.
MuddyWater (Earth Vetala)
Also tracked asMERCURY · Static Kitten · Seedworm and 4 more
MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least…
Mustang Panda (TA416)
Also tracked asRedDelta · BRONZE PRESIDENT · STATELY TAURUS and 11 more
Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to…
Mustard Tempest (DEV-0206)
Also tracked asTA569 · GOLD PRELUDE · UNC1543
Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered…
Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator