NEW: Group Profiler — instant APT intel lookup. Try it →

Threat groups N–P

13 of the 174 named threat groups in the MITRE ATT&CK knowledge base, alphabetically. Each links to its full profile: every alias with the report that used it, the techniques that are rare rather than universal, the closest groups by technique overlap, and live indicators where the malware families attributed to the group still have them.

  1. Naikon

    G0019ChinaEspionage14 techniques15 tools & malware

    Naikon is assessed to be a state-sponsored cyber espionage group attributed to the Chinese People’s Liberation Army’s (PLA) Chengdu Military Region…

  2. NEODYMIUM

    G00551 tools & malware

    NEODYMIUM is an activity group that conducted a campaign in May 2016 and has heavily targeted Turkish victims. The group has demonstrated similarity…

  3. Nomadic Octopus (DustSquad)

    G0133Russia7 techniques1 tools & malware

    Nomadic Octopus is a Russian-speaking cyber espionage threat group that has primarily targeted Central Asia, including local governments, diplomatic…

  4. OilRig (COBALT GYPSY)

    G0049IranEspionage76 techniques30 tools & malware1 live indicators

    Also tracked asIRN2 · APT34 · Helix Kitten and 7 more

    OilRig is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a…

  5. Orangeworm

    G00712 techniques8 tools & malware

    Orangeworm is a group that has targeted organizations in the healthcare sector in the United States, Europe, and Asia since at least 2015, likely for…

  6. Patchwork (Hangover Group)

    G0040Espionage41 techniques8 tools & malware5 live indicators

    Also tracked asDropping Elephant · Chinastrats · MONSOON and 1 more

    Patchwork is a cyber espionage group that was first observed in December 2015. While the group has not been definitively attributed, circumstantial…

  7. PittyTiger

    G0011China2 techniques5 tools & malware

    PittyTiger is a threat group believed to operate out of China that uses multiple different types of malware to maintain command and control.

  8. PLATINUM

    G006811 techniques3 tools & malware

    PLATINUM is an activity group that has targeted victims since at least 2009. The group has focused on targets associated with governments and related…

  9. Play

    G104026 techniques9 tools & malware

    Play is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical…

  10. POLONIUM (Plaid Rain)

    G1005Espionage7 techniques2 tools & malware

    POLONIUM is a Lebanon-based group that has primarily targeted Israeli organizations, including critical manufacturing, information technology, and…

  11. Poseidon Group

    G00338 techniques

    Poseidon Group is a Portuguese-speaking threat group that has been active since at least 2005. The group has a history of using information…

  12. PROMETHIUM (StrongPity)

    G005611 techniques2 tools & malware9 live indicators

    PROMETHIUM is an activity group focused on espionage that has been active since at least 2012. The group has conducted operations globally with a…

  13. Putter Panda (APT2)

    G0024ChinaEspionage4 techniques4 tools & malware4 live indicators

    Also tracked asMSUpdater

    Putter Panda is a Chinese threat group that has been attributed to Unit 61486 of the 12th Bureau of the PLA’s 3rd General Staff Department (GSD).

Back to the full directory·Interactive ATT&CK Group Profiler·APT IOC aggregator