NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups J–M

25 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. Ke3chang (APT15)

    G0004ChinaEspionage46 techniques11 tools & malware

    Also tracked asMirage · Vixen Panda · GREF and 4 more

    Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in…

  2. Kimsuky (Black Banshee)

    G0094North KoreaEspionage130 techniques19 tools & malware383 live indicators

    Also tracked asVelvet Chollima · Emerald Sleet · THALLIUM and 5 more

    Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially…

  3. LAPSUS$ (DEV-0537)

    G100443 techniques1 tools & malware

    Also tracked asStrawberry Tempest

    LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and…

  4. Lazarus Group (Labyrinth Chollima)

    G0032North KoreaEspionage93 techniques26 tools & malware251 live indicators

    Also tracked asHIDDEN COBRA · Guardians of Peace · ZINC and 2 more

    Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been…

  5. LazyScripter

    G014020 techniques7 tools & malware3,185 live indicators

    LazyScripter is threat group that has mainly targeted the airlines industry since at least 2018, primarily using open-source toolsets.

  6. Leafminer (Raspite)

    G0077Iran17 techniques4 tools & malware

    Leafminer is an Iranian threat group that has targeted government organizations and business entities in the Middle East since at least early 2017.

  7. Leviathan (MUDCARP)

    G0065ChinaEspionage50 techniques17 tools & malware

    Also tracked asKryptonite Panda · Gadolinium · BRONZE MOHAWK and 4 more

    Leviathan is a Chinese state-sponsored cyber espionage group that has been attributed to the Ministry of State Security's (MSS) Hainan State Security…

  8. Lotus Blossom (DRAGONFISH)

    G0030ChinaEspionage21 techniques9 tools & malware

    Also tracked asSpring Dragon · RADIUM · Raspberry Typhoon and 2 more

    Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related…

  9. LuminousMoth

    G1014ChinaEspionage28 techniques2 tools & malware

    LuminousMoth is a Chinese-speaking cyber espionage group that has been active since at least October 2020. LuminousMoth has targeted high-profile…

  10. Machete (APT-C-43)

    G0095Espionage11 techniques1 tools & malware

    Also tracked asEl Machete

    Machete is a suspected Spanish-speaking cyber espionage group that has been active since at least 2010. It has primarily focused its operations…

  11. Magic Hound (TA453)

    G0059IranEspionage78 techniques13 tools & malware64 live indicators

    Also tracked asCOBALT ILLUSION · Charming Kitten · ITG18 and 4 more

    Magic Hound is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the…

  12. Malteiro

    G102612 techniques1 tools & malware4 live indicators

    Malteiro is a financially motivated criminal group that is likely based in Brazil and has been active since at least November 2019. The group…

  13. Medusa Group

    G105157 techniques5 tools & malware

    Medusa Group has been active since at least 2021 and was initially operated as a closed ransomware group before evolving into a…

  14. menuPass (Cicada)

    G0045ChinaEspionage46 techniques25 tools & malware

    Also tracked asPOTASSIUM · Stone Panda · APT10 and 4 more

    menuPass is a threat group that has been active since at least 2006. Individual members of menuPass are known to have acted in association with the…

  15. Metador

    G10139 techniques2 tools & malware

    Metador is a suspected cyber espionage group that was first reported in September 2022. Metador has targeted a limited number of telecommunication…

  16. MirrorFace (Earth Kasha)

    G1054China43 techniques16 tools & malware

    MirrorFace is a People's Republic of China (PRC)-aligned cyberespionage actor believed to be a subgroup under the menuPass umbrella based on…

  17. Moafee

    G0002ChinaEspionage1 techniques1 tools & malware

    Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee…

  18. Mofang

    G0103ChinaEspionage6 techniques2 tools & malware3 live indicators

    Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been…

  19. Molerats (Operation Molerats)

    G0021Espionage16 techniques6 tools & malware1 live indicators

    Also tracked asGaza Cybergang

    Molerats is an Arabic-speaking, politically-motivated threat group that has been operating since 2012. The group's victims have primarily been in the…

  20. Moonstone Sleet (Storm-1789)

    G1036North KoreaEspionage30 techniques1 tools & malware138 live indicators

    Moonstone Sleet is a North Korean-linked threat actor executing both financially motivated attacks and espionage operations. The group previously…

  21. Moses Staff (DEV-0500)

    G1009Iran12 techniques4 tools & malware

    Also tracked asMarigold Sandstorm

    Moses Staff is a suspected Iranian threat group that has primarily targeted Israeli companies since at least September 2021. Moses Staff openly…

  22. MoustachedBouncer

    G1019Espionage8 techniques3 tools & malware

    MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.

  23. MuddyWater (Earth Vetala)

    G0069IranEspionage68 techniques21 tools & malware842 live indicators

    Also tracked asMERCURY · Static Kitten · Seedworm and 4 more

    MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least…

  24. Mustang Panda (TA416)

    G0129ChinaEspionage85 techniques23 tools & malware5 live indicators

    Also tracked asRedDelta · BRONZE PRESIDENT · STATELY TAURUS and 11 more

    Mustang Panda is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. Mustang Panda has been known to…

  25. Mustard Tempest (DEV-0206)

    G102012 techniques2 tools & malware152 live indicators

    Also tracked asTA569 · GOLD PRELUDE · UNC1543

    Mustard Tempest is an initial access broker that has operated the SocGholish distribution network since at least 2017. Mustard Tempest has partnered…

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator